MEDIUM
GHSA-27vg-33gh-4hwg
Actual Sync Server has an Authenticated Path Traversal
Quick fix
GHSA-27vg-33gh-4hwg — @actual-app/sync-server: upgrade to the fixed version with the command below.
npm install @actual-app/sync-server@26.3.0Details
# Description
Actual Sync Server allows authenticated users to upload files through `POST /sync/upload-user-file`. In versions prior to 26.3.0, improper validation of the user-controlled `x-actual-file-id` header means that traversal segments (`../`) can escape the intended directory and write files outside `userFiles`.
## Mitigations The vulnerability can be mitigated in prior versions by running the sync server in a filesystem sandbox.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/@actual-app/sync-server
Introduced in:
0Fixed in: 26.3.0Fix
npm install @actual-app/sync-server@26.3.0References
- https://github.com/actualbudget/actual/security/advisories/GHSA-27vg-33gh-4hwg[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-3089[ADVISORY]
- https://github.com/actualbudget/actual/pull/7067[WEB]
- https://github.com/actualbudget/actual/commit/18072e1d8b5281db43ded8b21433ee177bae9dfa[WEB]
- https://fluidattacks.com/advisories/fugue[WEB]
- https://github.com/actualbudget/actual[PACKAGE]