@actual-app/sync-server vulnerabilities
CVEs whose affected-version data names the @actual-app/sync-server package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-46700Medium· 4.3@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets
@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets
▾ Sunlitactual-app · @actual-app/sync-serverEPSS 0.34%via GHSA
CVE-2026-49229High· 8.3@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens
@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens
▾ Twilightactual-app · @actual-app/sync-serverEPSS 0.44%via GHSA