CVE-2026-46672
published 2026-07-07CVE-2026-46672: Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever…
PriorityP422medium4.6CVSS 3.1
AVLACLPRLUIRSCCLILAN
EPSS
0.19%
7.4th percentile
Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global --format csv option is passed, whose escapeCsv helper only handles RFC 4180 delimiter, quote, and newline escaping and does not neutralize standard CSV formula-injection prefixes. Any CLI command that streams an object array containing user-controlled strings, including transactions list, accounts list, payees list, categories list, tags list, category-groups list, rules list, schedules list, and query, can emit cells that auto-evaluate when the resulting CSV is opened in Excel, LibreOffice Calc, or Google Sheets, enabling data exfiltration and arbitrary formula execution. This issue is fixed in version 26.6.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actual-app | cli | >= 0 < 26.6.0 | 26.6.0 |
| actualbudget | actual | < 26.6.0 | 26.6.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Actual up to 26.5.x CSV Serializer output.ts escapeCsv deserialization
vuldb·2026-07-07·CVSS 4.6
CVE-2026-46672 [MEDIUM] Actual up to 26.5.x CSV Serializer output.ts escapeCsv deserialization
A vulnerability was found in Actual up to 26.5.x. It has been declared as problematic. The affected element is the function escapeCsv of the file packages/cli/src/output.ts of the component CSV Serializer. Executing a manipulation can lead to deserialization.
This vulnerability is registered as CVE-2026-46672. The attack needs to be launched locally. No exploit is available.
GHSA
@actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper
ghsa·2026-06-22
CVE-2026-46672 [MEDIUM] CWE-1236 @actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper
@actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper
## Summary
`@actual-app/cli` ships a hand-rolled CSV serializer in `packages/cli/src/output.ts` (used whenever the global `--format csv` option is passed) whose `escapeCsv` helper only handles RFC 4180 delimiter/quote/newline escaping. It does **not** neutralize the standard CSV formula-injection prefixes (`=`, `+`, `-`, `@`, `\t`, `\r`). Any CLI command that streams an object array containing user-controlled strings — `transactions list`, `accounts list`, `payees list`, `categories list`, `tags list`, `category-groups list`, `rules list`, `schedules list`, `query` — will emit cells that auto-evaluate when the resulting CSV is opened in Excel, LibreOffice Calc, or Google Sheets, enabli
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/actualbudget/actual/commit/068185751c03b42e726e3c60b718413d5f96c306https://github.com/actualbudget/actual/pull/7859https://github.com/actualbudget/actual/releases/tag/v26.6.0https://github.com/actualbudget/actual/security/advisories/GHSA-7gh7-258j-4mpqhttps://github.com/actualbudget/actual/security/advisories/GHSA-7gh7-258j-4mpq
2026-07-07
Published