PatchSiren

actualbudget CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM actualbudget CVE published 2026-07-07

CVE-2026-50179

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-07T22:16:52.923Z and has not been modified since then. The vulnerability affects Actual local-first personal finance tool versions prior to 26.6.0, allowing for potential data exfiltration via malicious CSV exports. Users should review and apply the patch to prevent exploitation.

HIGH actualbudget CVE published 2026-07-07

CVE-2026-49229

The Actual local-first personal finance app had a vulnerability in its OpenID multi-user mode. Prior to version 26.6.0, disabling a user did not invalidate existing session tokens, allowing a disabled user to continue accessing authenticated server endpoints. This issue is fixed in version 26.6.0. The vulnerability has a high impact on users of Actual local-first personal finance app, especially those usi [truncated]

HIGH actualbudget CVE published 2026-07-07

CVE-2026-50007

CVE-2026-50007 is a high-severity vulnerability in the Actual open-source personal finance application. Prior to version 26.7.0, a missing authorization issue allows a shared user with user_access on a budget file to perform owner-only file management actions. This issue is fixed in version 26.7.0. The vulnerability exists due to a missing authorization check in the requireFileAccess function, which treat [truncated]

MEDIUM actualbudget CVE published 2026-07-07

CVE-2026-46700

CVE-2026-46700 is an authentication bypass vulnerability in Actual local-first personal finance tool prior to version 26.6.0. The vulnerability allows an authenticated non-admin BASIC user in OpenID multi-user deployments to probe the secrets store and learn which admin-managed bank-sync integrations have been configured. This issue arises from the GET /secret/:name endpoint in @actual-app/sync-server not [truncated]

MEDIUM actualbudget CVE published 2026-07-07

CVE-2026-46672

The Actual local-first personal finance app, prior to version 26.6.0, contains a CSV injection vulnerability. The @actual-app/cli package includes a custom CSV serializer that fails to properly neutralize standard CSV formula-injection prefixes. This issue allows for the execution of arbitrary formulas when the resulting CSV file is opened in spreadsheet applications like Excel, LibreOffice Calc, or Googl [truncated]

MEDIUM actualbudget CVE published 2026-06-12

CVE-2026-43872

A path traversal vulnerability was discovered in Actual, an open-source personal finance application, prior to version 26.5.0. The vulnerability affects several endpoints and has been fixed in version 26.5.0.

MEDIUM actualbudget CVE published 2026-06-12

CVE-2026-42890

A vulnerability was discovered in the Actual open-source personal finance application for macOS, specifically in version 25.x, which is built on Electron 39.2.7. The issue arises from the ELECTRON_RUN_AS_NODE fuse not being disabled, allowing an attacker to invoke the signed Actual.app binary with the ELECTRON_RUN_AS_NODE=1 environment variable. This action converts the application into a Node.js REPL cap [truncated]

MEDIUM actualbudget CVE published 2026-06-12

CVE-2026-42604

A vulnerability was discovered in Actual Budget's sync-server versions <= 26.4.0. The `POST /openid/config` endpoint exposes the full OpenID Connect configuration, including the OAuth2 `client_secret`, to any caller who knows the bootstrap password. The endpoint lacks authentication and rate limiting, making the bootstrap password brute-forceable. This issue was fixed in version 26.5.0.