7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether @actual-app/sync-server is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.3
CVE-2026-49229
@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens
MEDIUM 4.3
CVE-2026-46700
@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets
MEDIUM 4.2
GHSA-xvp7-8vm8-xfxx
Actual Sync-server Gocardless service is logging sensitive data including bearer tokens and account numbers
HIGH 8.8
CVE-2026-33318
Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers
UNKNOWN
CVE-2026-3089
Actual Sync Server has an Authenticated Path Traversal
UNKNOWN
CVE-2026-27638
@actual-app/sync-server: Missing authorization in sync endpoints allows cross-user budget file access in multi-user mode
UNKNOWN
CVE-2026-27584
ActualBudget server is Missing Authentication for SimpleFIN and Pluggy AI bank sync endpoints
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes