PT-2026-47599 · Actual · Actual
CVE-2026-42890
·
Published
2026-06-08
·
Updated
2026-06-12
CVSS v4.0
4.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Actual versions prior to 26.5.0
Description
In the macOS desktop application, the
ELECTRON RUN AS NODE fuse is not disabled. This allows an attacker who can place a file on disk or control command-line arguments to invoke the signed Actual.app binary with the ELECTRON RUN AS NODE=1 environment variable set. This action converts the application into a Node.js REPL (Read-Eval-Print Loop), which is an interactive shell that takes single expressions as input and returns their value, capable of executing arbitrary code. The executed code inherits the application's entitlements and code signature, effectively bypassing the macOS Gatekeeper review process. This enables the execution of Node.js scripts under the application's bundle ID and signed identity, granting access to entitlements such as network, file access, keychain, and automation.Recommendations
Update to version 26.5.0.
Exploit
Fix
Protection Mechanism Failure
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Actual