@actual-app/sync-server
This hub aggregates every CVE we track for @actual-app/sync-server, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
3
CVEs tracked
0
Critical
2
High
0
In CISA KEV
Severity distribution
HIGH2MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2
1
0
0
0
0
2024-082026-07
Latest CVEs
The 3 most recently published vulnerabilities affecting @actual-app/sync-server.
- CVE-2026-3089Actual Sync Server 26.2.1 - Authenticated Path Traversal6.5
- CVE-2026-27638ActualBudget missing authorization in sync endpoints allows cross-user budget file access in multi-user mode7.1
- CVE-2026-27584ActualBudget server is Missing Authentication for SimpleFIN and Pluggy AI bank sync endpoints7.5
Product normalization is registry-driven with AI assist and human review. How it works