These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-07T22:16:52.923Z and has not been modified since then. The vulnerability affects Actual local-first personal finance tool versions prior to 26.6.0, allowing for potential data exfiltration via malicious CSV exports. Users should review and apply the patch to prevent exploitation.
The Actual local-first personal finance app had a vulnerability in its OpenID multi-user mode. Prior to version 26.6.0, disabling a user did not invalidate existing session tokens, allowing a disabled user to continue accessing authenticated server endpoints. This issue is fixed in version 26.6.0. The vulnerability has a high impact on users of Actual local-first personal finance app, especially those usi [truncated]
CVE-2026-50007 is a high-severity vulnerability in the Actual open-source personal finance application. Prior to version 26.7.0, a missing authorization issue allows a shared user with user_access on a budget file to perform owner-only file management actions. This issue is fixed in version 26.7.0. The vulnerability exists due to a missing authorization check in the requireFileAccess function, which treat [truncated]
CVE-2026-46700 is an authentication bypass vulnerability in Actual local-first personal finance tool prior to version 26.6.0. The vulnerability allows an authenticated non-admin BASIC user in OpenID multi-user deployments to probe the secrets store and learn which admin-managed bank-sync integrations have been configured. This issue arises from the GET /secret/:name endpoint in @actual-app/sync-server not [truncated]
The Actual local-first personal finance app, prior to version 26.6.0, contains a CSV injection vulnerability. The @actual-app/cli package includes a custom CSV serializer that fails to properly neutralize standard CSV formula-injection prefixes. This issue allows for the execution of arbitrary formulas when the resulting CSV file is opened in spreadsheet applications like Excel, LibreOffice Calc, or Googl [truncated]
A path traversal vulnerability was discovered in Actual, an open-source personal finance application, prior to version 26.5.0. The vulnerability affects several endpoints and has been fixed in version 26.5.0.
A vulnerability was discovered in the Actual open-source personal finance application for macOS, specifically in version 25.x, which is built on Electron 39.2.7. The issue arises from the ELECTRON_RUN_AS_NODE fuse not being disabled, allowing an attacker to invoke the signed Actual.app binary with the ELECTRON_RUN_AS_NODE=1 environment variable. This action converts the application into a Node.js REPL cap [truncated]
A vulnerability was discovered in Actual Budget's sync-server versions <= 26.4.0. The `POST /openid/config` endpoint exposes the full OpenID Connect configuration, including the OAuth2 `client_secret`, to any caller who knows the bootstrap password. The endpoint lacks authentication and rate limiting, making the bootstrap password brute-forceable. This issue was fixed in version 26.5.0.