CVE-2026-49229
- EPSS 0.25%
- Veröffentlicht 07.07.2026 20:59:34
- Zuletzt bearbeitet 09.07.2026 15:16:35
Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks future OpenID login for that identity, while existing Actual session tokens for the disabled user remain valid. The shared session ...
CVE-2026-50179
- EPSS 0.17%
- Veröffentlicht 07.07.2026 20:58:16
- Zuletzt bearbeitet 09.07.2026 16:16:42
Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-controlled Payee, Notes, Account, and Category strings to csv-stringify w...
CVE-2026-46700
- EPSS 0.2%
- Veröffentlicht 07.07.2026 20:56:39
- Zuletzt bearbeitet 08.07.2026 15:28:15
Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session and does not verify the caller is an admin, while the sibling POST /secret/ hand...
CVE-2026-46672
- EPSS 0.13%
- Veröffentlicht 07.07.2026 20:55:02
- Zuletzt bearbeitet 08.07.2026 15:28:15
Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global --format csv option is passed, whose escapeCsv helper only handles RFC 4180 delim...
CVE-2026-50007
- EPSS 0.25%
- Veröffentlicht 07.07.2026 20:53:21
- Zuletzt bearbeitet 08.07.2026 15:28:15
Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared user with user_access on a budget file to perform owner-only file management actions. A non-owner shared user can call file-manageme...
CVE-2026-43872
- EPSS 0.3%
- Veröffentlicht 12.06.2026 19:05:42
- Zuletzt bearbeitet 16.06.2026 15:35:16
Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path traversal vulnerability. Version 26.5.0 fixes the issue.
CVE-2026-42890
- EPSS 0.13%
- Veröffentlicht 12.06.2026 18:58:42
- Zuletzt bearbeitet 16.06.2026 15:35:16
Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing an attacker who can place a file on disk or control command-line ...
CVE-2026-42604
- EPSS 0.4%
- Veröffentlicht 12.06.2026 18:42:38
- Zuletzt bearbeitet 16.06.2026 15:35:16
Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the full OpenID Connect configuration—including the OAuth2 `client_secret`—to any caller who knows the bootstr...
CVE-2026-33318
- EPSS 0.47%
- Veröffentlicht 24.04.2026 02:13:47
- Zuletzt bearbeitet 27.04.2026 15:01:34
Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on servers migrated from password authentication to OpenID Connect. Three weaknesses combine: `POST /accou...
CVE-2026-3089
- EPSS 0.38%
- Veröffentlicht 09.03.2026 14:08:55
- Zuletzt bearbeitet 09.04.2026 21:01:46
Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to 26.3.0, improper validation of the user-controlled x-actual-file-id header means that traversal segments (../) can escape the inte...