Published Jun 22, 2026
CVSS
HIGH
EPSS
Affected packages
@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens