Executive brief
monetr is a budgeting application used to track and plan recurring expenses. A flaw in the software allows users to bypass restrictions and hide or 'soft-delete' imported financial transactions that are supposed to be permanent. This can lead to inaccurate financial records, compromised bookkeeping integrity, and the loss of a reliable audit trail for synced expenses.
Technical details
The vulnerability is an improper authorization and integrity flaw (CWE-285) within the transaction update (PUT) path. While the application correctly blocks the deletion of synced transactions via the dedicated DELETE handler, the PUT endpoint fails to filter server-managed fields. An authenticated attacker can submit a full Transaction object containing a user-supplied 'deletedAt' value. The server persists this field, effectively soft-deleting the record and hiding it from standard views. This bypasses the immutability policy intended for imported transaction records. The issue is resolved in version 1.12.3.
Affected products
- monetr monetr < 1.12.3
Timeline
- 2026-04-07: advisory: GitHub Security Advisory published
- 2026-04-08: disclosed: CVE-2026-39901 published
- 2026-04-08: patched: Fix released in version 1.12.3