All vulnerabilities

GHSA-3F62-QV96-4P78

npm · @actual-app/sync-server

Summary

@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets

References