Description
A electron run as node vulnerability was identified in actual (macOS application, version 25.x (Electron 39.2.7)).
Vulnerability Type: Electron Run As Node
Recommendation
Update the actual package to the latest compatible version. Followings are version details:
- Affected version(s): < 26.5.0
- Patched version(s): 26.5.0
References
- GHSA-7rvm-xjpp-63r9
- actualbudget.org
- CVE-2026-42890
- CWE-250
- CWE-693
- CWE-94
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- OneUptime:: node:vm sandbox escape in probe allows any project member to achieve RCE - CVE-2026-27574
- dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration - CVE-2026-34725
- Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover - @haxtheweb/video-player - CVE-2026-46396
- Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host - CVE-2026-71319
You might also like:
- Tags:
- npm
- actual
Anything's wrong? Let us know Last updated on June 12, 2026


