Vulnerability Description
Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing an attacker who can place a file on disk or control command-line arguments to invoke the signed Actual.app binary with the ELECTRON_RUN_AS_NODE=1 environment variable set. This converts the application into a Node.js REPL capable of executing arbitrary code that inherits the application's entitlements and code signature, bypassing macOS Gatekeeper review. Version 26.5.0 patches the issue.
Related Weaknesses (CWE)
References
- https://actualbudget.org/blog/release-26.5.0
- https://github.com/actualbudget/actual/security/advisories/GHSA-7rvm-xjpp-63r9
FAQ
What is CVE-2026-42890?
CVE-2026-42890 is a documented vulnerability. Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing an attacker who...
How severe is CVE-2026-42890?
CVSS scoring is not yet available for CVE-2026-42890. Check NVD for updates.
Is there a patch for CVE-2026-42890?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.