GHSA-7rvm-xjpp-63r9

Suggest an improvement
Source
https://github.com/advisories/GHSA-7rvm-xjpp-63r9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-7rvm-xjpp-63r9/GHSA-7rvm-xjpp-63r9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7rvm-xjpp-63r9
Aliases
Published
2026-06-08T18:21:26Z
Modified
2026-06-12T22:15:09Z
Severity
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
actual Allows Electron to Run As Node
Details

Summary

A electron run as node vulnerability was identified in actual (macOS application, version 25.x (Electron 39.2.7)).

Vulnerability Type: Electron Run As Node

Description

ELECTRON_RUN_AS_NODE fuse enabled (Electron 39.2.7) — app can be converted to Node.js REPL for arbitrary code execution

Impact

An attacker who can place a file on disk or control command-line arguments can invoke the signed Actual.app binary with ELECTRON_RUN_AS_NODE=1 to execute arbitrary Node.js code inheriting the apps entitlements and code signature. This bypasses macOS Gatekeeper review of the payload: the Node.js script runs as Actual, under Actuals bundle ID and signed identity, and has access to any entitlements the app carries (network, file access, keychain, automation). Combined with any downloader (browser, mail attachment, Slack link) this becomes a signed-binary-abuse primitive on every Mac with Actual installed.

Database specific
{
    "cwe_ids":  [
        "CWE-250",
        "CWE-693",
        "CWE-94"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-08T18:21:26Z",
    "nvd_published_at":  "2026-06-12T20:16:45Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / actual

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
26.5.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-7rvm-xjpp-63r9/GHSA-7rvm-xjpp-63r9.json"