PT-2026-47599 · Actual · Actual

CVE-2026-42890

·

Published

2026-06-08

·

Updated

2026-06-12

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Actual versions prior to 26.5.0
Description In the macOS desktop application, the ELECTRON RUN AS NODE fuse is not disabled. This allows an attacker who can place a file on disk or control command-line arguments to invoke the signed Actual.app binary with the ELECTRON RUN AS NODE=1 environment variable set. This action converts the application into a Node.js REPL (Read-Eval-Print Loop), which is an interactive shell that takes single expressions as input and returns their value, capable of executing arbitrary code. The executed code inherits the application's entitlements and code signature, effectively bypassing the macOS Gatekeeper review process. This enables the execution of Node.js scripts under the application's bundle ID and signed identity, granting access to entitlements such as network, file access, keychain, and automation.
Recommendations Update to version 26.5.0.

Exploit

Fix

Protection Mechanism Failure

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42890
GHSA-7RVM-XJPP-63R9

Affected Products

Actual