VDB
Sign up

package

npm/@actual-app/sync-server

pkg:npm/%40actual-app/sync-server

MEDIUM4.3npm
GHSA-3f62-qv96-4p78· CVE-2026-46700

@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets

Modified: 9/10/2026

MEDIUMnpm
GHSA-qmjj-p7m9-wjrv· CVE-2026-27638

@actual-app/sync-server: Missing authorization in sync endpoints allows cross-user budget file access in multi-user mode

Modified: 2/28/2026

MEDIUM4.2npm
GHSA-xvp7-8vm8-xfxx

Actual Sync-server Gocardless service is logging sensitive data including bearer tokens and account numbers

Modified: 9/10/2026