Executive brief
TaxHacker is a self-hosted AI accounting application that analyzes receipts and invoices. The email synchronization feature allows users to configure custom IMAP email servers but fails to validate the host and port parameters, enabling an attacker to craft a malicious server configuration that forces the application to make network connections to internal or arbitrary systems. This can be exploited to scan internal networks, fingerprint services, or bypass firewalls.
Technical details
A server-side request forgery (SSRF) vulnerability exists in the email sync component of TaxHacker, specifically in the buildImapConfig() function (lib/email-sync/imap-client.ts). The addEmailServerAction() function in app/(app)/apps/email/actions.ts accepts user-controlled host and port parameters without validation and stores them in the database. When email synchronization is triggered or when testImapConnection() is called, these untrusted parameters are passed directly to the imap-simple library's imaps.connect() method, which establishes a TCP connection to the attacker-specified host and port. An authenticated user can exploit this to perform SSRF attacks against internal services, scan internal networks, or fingerprint running services. The vulnerability requires authentication to exploit (PR:L in CVSS vector) and results in information disclosure through connection probing. A fix has been proposed but not yet merged into the codebase.
Affected products
- vas3k TaxHacker up to 0.8.2
Timeline
- 2026-08-23: disclosed
- 2026-07-07: other: Issue opened on GitHub