OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-57449

HIGH · CVSS 7.1 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The Actual Sync Server's CORS proxy in versions prior to 26.7.0 is vulnerable, allowing authenticated users to access private GitHub resources by improperly validating API requests against a repository allowlist. This flaw enables users to exploit the proxy to read sensitive data from repositories that should not be accessible, posing a significant risk to the confidentiality of private GitHub resources. Organizations using Actual prior to version 26.7.0 should prioritize updating to the latest version to mitigate this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57449
Severity
HIGH
CVSS
7.1
EPSS
0.21%
GitHub

Original NVD Description

Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authenticated users fetch resources only from repositories listed in the official plugin allowlist. When `ACTUAL_GITHUB_TOKEN` is configured, the proxy automatically attaches the server's GitHub token to GitHub requests. The GitHub API allowlist check uses a raw `startsWith()` prefix test for `/repos/{owner}/{repo}` without requiring a path boundary after the repository name. If an allowlisted public plugin repository is `https://github.com/acme/plugin`, the proxy also accepts GitHub API URLs. Those URLs are outside the allowlisted repository but still pass because their API path starts with `/repos/acme/plugin`. The proxy then forwards the request with the server's `ACTUAL_GITHUB_TOKEN`, allowing any authenticated Actual user to read private GitHub resources reachable by that token. Version 26.7.0 fixes the issue.