A high-severity vulnerability affecting @actual-app/sync-server versions <= 26.6.0, CVE-2026-57449 with a CVSS score of 7.1, affects the CORS proxy component of Actual Sync Server, allowing authenticated users to read private GitHub resources reachable by the server's token due to an allowlist bypass through prefix-matching repository names. This enables exposure of source code, repository metadata, release data, deployment files, and accidentally committed secrets, potentially leading to follow-on compromise of production infrastructure or supply-chain release assets. The vulnerability arises from a raw `startsWith` prefix test for `` without requiring a path boundary after the repository name, allowing any authenticated Actual user to read private GitHub resources reachable by that token. The affected endpoint is mounted only when the CORS proxy is enabled through `ACTUAL_CORS_PROXY_ENABLED`, and the GitHub token is configured through `ACTUAL_GITHUB_TOKEN`. To exploit this vulnerability, an attacker needs a valid Actual session token and must ensure that the official plugin allowlist contains a public repo whose owner and repo name are a prefix of the private target repo. The recommended remediation involves parsing and comparing GitHub API repository path segments exactly, replacing the vulnerable `startsWith` check with a boundary-aware comparison, and adding regression tests to demonstrate the fix.
We recommend you to update Actual Sync Server to version 26.7.0.[/subscribe_to_unlock_form]
A high-severity vulnerability affecting @actual-app/sync-server versions <= 26.6.0, CVE-2026-57449 with a CVSS score of 7.1, affects the CORS proxy component of Actual Sync Server, allowing authenticated users to read private GitHub resources reachable by the server's token due to an allowlist bypass through prefix-matching repository names. This enables exposure of source code, repository metadata, release data, deployment files, and accidentally committed secrets, potentially leading to follow-on compromise of production infrastructure or supply-chain release assets. The vulnerability arises from a raw `startsWith` prefix test for `` without requiring a path boundary after the repository name, allowing any authenticated Actual user to read private GitHub resources reachable by that token. The affected endpoint is mounted only when the CORS proxy is enabled through `ACTUAL_CORS_PROXY_ENABLED`, and the GitHub token is configured through `ACTUAL_GITHUB_TOKEN`. To exploit this vulnerability, an attacker needs a valid Actual session token and must ensure that the official plugin allowlist contains a public repo whose owner and repo name are a prefix of the private target repo. The recommended remediation involves parsing and comparing GitHub API repository path segments exactly, replacing the vulnerable `startsWith` check with a boundary-aware comparison, and adding regression tests to demonstrate the fix.
We recommend you to update Actual Sync Server to version 26.7.0.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]