{"id":"CVE-2026-42890","aliases":["GHSA-7rvm-xjpp-63r9"],"url":"https://o3.security/vulnerability/CVE-2026-42890","summary":"actual Allows Electron to Run As Node","details":"Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing an attacker who can place a file on disk or control command-line arguments to invoke the signed Actual.app binary with the ELECTRON_RUN_AS_NODE=1 environment variable set. This converts the application into a Node.js REPL capable of executing arbitrary code that inherits the application's entitlements and code signature, bypassing macOS Gatekeeper review. Version 26.5.0 patches the issue.","published":"2026-06-12T18:58:42.239Z","modified":"2026-08-12T03:51:27.267847340Z","cvss":null,"epss":{"score":0.00126,"percentile":0.02585,"asOf":"2026-09-02"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"actual","fixedVersion":"26.5.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42890.json"},{"type":"ADVISORY","url":"https://github.com/actualbudget/actual/security/advisories/GHSA-7rvm-xjpp-63r9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42890"},{"type":"ARTICLE","url":"https://actualbudget.org/blog/release-26.5.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:27.267847340Z"}}