@actual-app/sync-server
npm7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @actual-app/sync-serverpage 1 of 1
- CVE-2026-27584HIGHCVSS 7.5EG 7.5fixed in 26.2.12026-02-24
Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualBudget server component allows any unauthenticated user to query the SimpleFIN and Pluggy.ai integration endpoints and r…
- CVE-2026-27638HIGHCVSS 7.1EG 7.1fixed in 26.2.12026-02-26
Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify that the authenticated user owns or has access to the file being operated on. Any authenti…
- CVE-2026-3089MEDIUMCVSS 6.5EG 6.5fixed in 26.3.02026-03-09
Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to 26.3.0, improper validation of the user-controlled x-actual-file-id header means that traversal segments (../) can esca…
- CVE-2026-33318HIGHCVSS 8.8EG 8.8fixed in 26.4.02026-04-24
Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on servers migrated from password authentication to OpenID Connect. Three weaknesses combine: `…
- CVE-2026-46700MEDIUMCVSS 4.3EG 4.3fixed in 26.6.02026-06-22
Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session and does not verify the caller is an admin, while the sibling POST /s…
- CVE-2026-49229HIGHCVSS 8.3EG 8.3fixed in 26.6.02026-06-22
Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks future OpenID login for that identity, while existing Actual session tokens for the disabled user remain valid. The shar…
- CVE-2026-57449HIGHCVSS 7.1EG 7.1fixed in 26.7.02026-09-25
Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authenticated users fetch resources only from repositories listed in the official plugin allowlist. When `ACTUAL_GITHUB_TOKE…
Check whether @actual-app/sync-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @actual-app/sync-server CVEs against the assets you own.
Book a Demo →