[CVE-2026-78061] A vulnerability was determined in vas3k TaxHacker up to 0.8.

CVE-2026-78061 | CVSS: 6.3 | 严重级别: MEDIUM

A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of the component Email Sync. Executing a manipulation of the argument host/port can lead to server-side request forgery. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.

参考链接:
https://github.com/vas3k/TaxHacker/
https://github.com/vas3k/TaxHacker/issues/148
https://github.com/vas3k/TaxHacker/pull/170

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部