CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2026-57449: @actual-app/sync-server <= 26.6.0

CVE-2026-57449 affects @actual-app/sync-server. EPSS 0.00207 (percentile 0.09846), scored 2026-10-06. Affected range: <= 26.6.0. Fixed version: 26.7.0.

Affected technology

@actual-app/sync-server · <= 26.6.0
Vendor not specified by the source

Description’s affected range: Through the Server GitHub Token ## Summary Actual Sync Server's CORS proxy is intended to let authenticated users fetch resources only from repositories listed in the official plugin allowlist

Component: Not specified by the source

What an attacker can do

Any authenticated Actual user can read private GitHub resources reachable by that token.

Published

Product
@actual-app/sync-server
CCR priority
0.1 /100 (P5)
EPSS
0.00207 · percentile 0.09846 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-57449.html