SCA: security update for @actual-app/sync-server (GHSA-m62c-5q34-f3cf)

high Tenable Self-Hosted Container Security Plugin ID 473730

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is
intended to let authenticated users fetch resources only from repositories listed in the official plugin
allowlist. When `ACTUAL_GITHUB_TOKEN` is configured, the proxy automatically attaches the server's GitHub
token to GitHub requests. The GitHub API allowlist check uses a raw `startsWith()` prefix test for
`/repos/{owner}/{repo}` without requiring a path boundary after the repository name. If an allowlisted
public plugin repository is `https://github.com/acme/plugin`, the proxy also accepts GitHub API URLs.
Those URLs are outside the allowlisted repository but still pass because their API path starts with
`/repos/acme/plugin`. The proxy then forwards the request with the server's `ACTUAL_GITHUB_TOKEN`,
allowing any authenticated Actual user to read private GitHub resources reachable by that token. Version
26.7.0 fixes the issue. (CVE-2026-57449)

Solution

Update the @actual-app/sync-server library and its related packages to version 26.7.0 or later.

See Also

https://github.com/advisories/GHSA-m62c-5q34-f3cf

Plugin Details

Severity: High

ID: 473730

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/7/2026

Updated: 10/7/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.6

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2026-57449

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7.1

Threat Score: 4.9

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/7/2026

Vulnerability Publication Date: 9/25/2026

Reference Information

CVE: CVE-2026-57449