Junglewise Threat Intelligence

CVE-2026-50179: Actual Budget CSV formula injection in transaction export

CVE-2026-50179 · Severity: medium · CVSS 4.2 · Published 2026-07-07

Technologies: Actualbudget Actual Budget. Vendors: npm, Actual Budget.

Executive brief

Actual Budget, a personal finance and budgeting tool, is vulnerable to a security flaw where malicious data can be hidden within transaction records. If a user imports a specially crafted bank statement or file and later exports their data to a spreadsheet (like Excel or Google Sheets), the malicious data can execute as a formula. This could allow an attacker to trick the user into clicking a link that steals sensitive financial information or displays fraudulent transaction details.

Technical details

A CSV injection (Formula Injection) vulnerability exists in Actual Budget's `exportToCSV` and `exportQueryToCSV` functions within `packages/loot-core/src/server/transactions/export/export-to-csv.ts`. The application fails to neutralize formula-triggering characters (=, +, -, @, tab, or carriage return) in user-controlled fields such as Payee, Notes, Account, and Category before passing them to the `csv-stringify` library. An attacker can plant malicious payloads by providing a crafted import file (OFX, QIF, CSV) or via the API. When a victim exports the budget and opens it in Excel, LibreOffice, or Google Sheets, these strings execute as formulas (e.g., `=HYPERLINK`, `=WEBSERVICE`), enabling the exfiltration of adjacent cell data to an attacker-controlled server. The issue is fixed in version 26.6.0 by implementing a `cast.string` callback to prefix such strings with a single quote.

Affected products

  • actualbudget Actual Budget < 26.6.0

Timeline

  • 2026-05-16: patched: Fix committed to repository
  • 2026-06-01: advisory: Version 26.6.0 released
  • 2026-06-12: disclosed: Security advisory published on GitHub
  • 2026-07-07: other: NVD publication date

References

Related threats