Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
actual Allows Electron to Run As Node
Vulnerability Description
Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing an attacker who can place a file on disk or control command-line arguments to invoke the signed Actual.app binary with the ELECTRON_RUN_AS_NODE=1 environment variable set. This converts the application into a Node.js REPL capable of executing arbitrary code that inherits the application's entitlements and code signature, bypassing macOS Gatekeeper review. Version 26.5.0 patches the issue.
CVSS Information
N/A
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
actualbudget actual 代码注入漏洞
Vulnerability Description
actualbudget actual是actualbudget团队开源的一个个人财务管理应用。 actualbudget actual 26.5.0之前版本存在代码注入漏洞,该漏洞源于Electron的ELECTRON_RUN_AS_NODE fuse未禁用,允许攻击者将文件放置在磁盘上或控制命令行参数,通过设置该环境变量将应用转换为Node.js REPL,从而执行任意代码,绕过macOS Gatekeeper审查。
CVSS Information
N/A
Vulnerability Type
N/A