CVE-2026-57449
— UNSCOREDpublic exploit availablePublished 2026-09-25 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authenticated users fetch resources only from repositories listed in the official plugin allowlist. When `ACTUAL_GITHUB_TOKEN` is configured, the proxy automatically attaches the server's GitHub token to GitHub requests. The GitHub API allowlist check uses a raw `startsWith()` prefix test for `/repos/{owner}/{repo}` without requiring a path boundary after the repository name. If an allowlisted public plugin repository is `https://github.com/acme/plugin`, the proxy also accepts GitHub API URLs. Those URLs are outside the allowlisted repository but still pass because their API path starts with `/repos/acme/plugin`. The proxy then forwards the request with the server's `ACTUAL_GITHUB_TOKEN`, allowing any authenticated Actual user to read private GitHub resources reachable by that token. Version 26.7.0 fixes the issue.
Weaknesses
CWE-200, CWE-284, CWE-863
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-100906PoC
- MEDIUMCVE-2026-100907PoC
- MEDIUMCVE-2026-101055PoC
- MEDIUMCVE-2026-101083
- MEDIUMCVE-2026-101143
- MEDIUMCVE-2026-101146
- MEDIUMCVE-2026-102845PoC
- UNSCOREDCVE-2026-56729PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.