npm
@actual-app/sync-server
4 known vulnerabilities · 0 critical · 0 high
@actual-app/sync-server: Missing authorization in sync endpoints allows cross-user budget file access in multi-user mode
Published Feb 27, 2026
ActualBudget server is Missing Authentication for SimpleFIN and Pluggy AI bank sync endpoints
Published Feb 24, 2026
GHSA-prp4-2f49-fcgp
Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers
Published Apr 23, 2026
Check your entire dependency tree at onceRun dependency scan →