CVE-2026-46672
Last modified
CVE-2026-46672 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global --format csv option is passed, whose escapeCsv helper only handles RFC 4180 delimiter, quote, and newline escaping and does not neutralize standard CSV formula-injection prefixes. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global --format csv option is passed, whose escapeCsv helper only handles RFC 4180 delimiter, quote, and newline escaping and does not neutralize standard CSV formula-injection prefixes. Any CLI command that streams an object array containing user-controlled strings, including transactions list, accounts list, payees list, categories list, tags list, category-groups list, rules list, schedules list, and query, can emit cells that auto-evaluate when the resulting CSV is opened in Excel, LibreOffice Calc, or Google Sheets, enabling data exfiltration and arbitrary formula execution. This issue is fixed in version 26.6.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| actualbudget | actual | < 26.6.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-46672?
How severe is CVE-2026-46672?
How do I fix CVE-2026-46672?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4666The wpForo Forum plugin for WordPress is vulnerable to unaut…6.5
- CVE-2026-46668SpiceDB is an open source database system for creating and m…2.3
- CVE-2026-46669OpenVM is a performant and modular zkVM framework built for …7.5
- CVE-2026-4667HP System Optimizer might potentially be vulnerable to escal…7.3
- CVE-2026-46670YesWiki is a wiki system written in PHP. Prior to version 4.…9.8
- CVE-2026-46671Rust OneNote File Parser is a parser for Microsoft OneNote f…4.4
- CVE-2026-46673Russh is a Rust SSH client & server library. Prior to versio…7.5
- CVE-2026-46678Pydantic AI is a Python agent framework for building Generat…5.9
- CVE-2026-46679libp2p is a JavaScript Implementation of libp2p networking s…7.5
- CVE-2026-4668The Booking for Appointments and Events Calendar - Amelia pl…6.5
- CVE-2026-46680containerd is an open-source container runtime. In versions …7.8
- CVE-2026-46681@nevware21/ts-utils is a comprehensive TypeScript/JavaScript…7.2
Are you affected by CVE-2026-46672?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
