Actual 是一款以本地优先的个人财务管理工具。在版本 26.7.0 之前,Actual Sync Server 中的 CORS 代理本意是仅允许经过身份验证的用户从官方插件白名单中列出的仓库获取资源。当配置了 环境变量时,该代理会自动在针对 GitHub 的请求中附加服务器持有的 GitHub 令牌。 然而,GitHub API 白名单检查仅使用原始的 前缀匹配逻辑来验证 路径,且未在仓库名称后要求严格的路径边界(例如 或结束符)。因此,如果一个白名单中的公共插件仓库为 ,那么代理也会接受以 开头的 GitHu
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| actualbudget | actual | < 26.7.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| actualbudget | actual | < 26.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet