Get real-time updates on Telegram
P5Verified
CVE-2026-57449: @actual-app/sync-server <= 26.6.0
CVE-2026-57449 affects @actual-app/sync-server. EPSS 0.00207 (percentile 0.09846), scored 2026-10-06. Affected range: <= 26.6.0. Fixed version: 26.7.0.
Affected technology
@actual-app/sync-server · <= 26.6.0
Vendor not specified by the source
Description’s affected range: Through the Server GitHub Token ## Summary Actual Sync Server's CORS proxy is intended to let authenticated users fetch resources only from repositories listed in the official plugin allowlist
Component: Not specified by the source
What an attacker can do
Any authenticated Actual user can read private GitHub resources reachable by that token.
- Product
- @actual-app/sync-server
- CCR priority
- 0.1 /100 (P5)
- EPSS
- 0.00207 · percentile 0.09846 · 2026-10-06
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-08 08:50:52.119177+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-57449.html