VYPR

sync-server

by Actual App

CVEs (1)

  • CVE-2026-46700medJun 22, 2026
    risk 0.26cvss epss

    ## Summary In `@actual-app/sync-server`, the `GET /secret/:name` endpoint (`app-secrets.js:53`) checks only that the caller has a valid session — it does not verify the caller is an admin. The sibling `POST /secret/` handler does enforce an admin check in OpenID mode,…