Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-57449— Actual Sync Server: CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Private Repositories Through the Server GitHub Token

Quick assessment

Affected
actualbudget actual
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Actual 是一款以本地优先的个人财务管理工具。在版本 26.7.0 之前,Actual Sync Server 中的 CORS 代理本意是仅允许经过身份验证的用户从官方插件白名单中列出的仓库获取资源。当配置了 环境变量时,该代理会自动在针对 GitHub 的请求中附加服务器持有的 GitHub 令牌。 然而,GitHub API 白名单检查仅使用原始的 前缀匹配逻辑来验证 路径,且未在仓库名称后要求严格的路径边界(例如 或结束符)。因此,如果一个白名单中的公共插件仓库为 ,那么代理也会接受以 开头的 GitHu

CVSS 7.1 · High EPSS 0.21% · P10

Possible ATT&CK Techniques 1 AI

T1552.004 · Private Keys

Affected Version Matrix 1

VendorProduct Version RangeStatus
actualbudget actual < 26.7.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-57449

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Actual Sync Server: CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Private Repositories Through the Server GitHub Token
Source: CVE Program / CVE List V5
Vulnerability Description
Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authenticated users fetch resources only from repositories listed in the official plugin allowlist. When `ACTUAL_GITHUB_TOKEN` is configured, the proxy automatically attaches the server's GitHub token to GitHub requests. The GitHub API allowlist check uses a raw `startsWith()` prefix test for `/repos/{owner}/{repo}` without requiring a path boundary after the repository name. If an allowlisted public plugin repository is `https://github.com/acme/plugin`, the proxy also accepts GitHub API URLs. Those URLs are outside the allowlisted repository but still pass because their API path starts with `/repos/acme/plugin`. The proxy then forwards the request with the server's `ACTUAL_GITHUB_TOKEN`, allowing any authenticated Actual user to read private GitHub resources reachable by that token. Version 26.7.0 fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
actualbudget actual < 26.7.0 -

II. Public POCs for CVE-2026-57449

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-57449

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-57449 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-57449

No comments yet


Leave a comment