PT-2026-99134 · Unknown · Actual Sync Server

CVE-2026-57449

·

Published

2026-09-25

·

Updated

2026-09-28

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Actual Sync Server versions prior to 26.7.0
Description The CORS proxy in Actual Sync Server allows authenticated users to fetch resources from repositories on an official plugin allowlist. When the ACTUAL GITHUB TOKEN is configured, the proxy attaches this token to GitHub requests. The allowlist check uses a startsWith() prefix test for the /repos/{owner}/{repo} endpoint without enforcing a path boundary after the repository name. This allows requests to GitHub API URLs that start with the allowlisted path but are actually outside the intended repository. Consequently, authenticated users can read private GitHub resources accessible by the server's ACTUAL GITHUB TOKEN.
Recommendations Update to version 26.7.0.

Exploit

Fix

Information Disclosure

Improper Access Control

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57449
GHSA-M62C-5Q34-F3CF

Affected Products

Actual Sync Server