{"api_version":"v1","generated_at":"2026-10-09T09:50:00+00:00","product":{"cve_count":12,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-actualbudget-actual-5c32aa35df8d","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/actual","name":"actual","next_cursor":null,"observations":[{"affected":"actual: < 26.7.0","affected_versions_present":true,"cve_id":"CVE-2026-57449","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-57449","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-28T13:07:46.380Z","patch_url":"","primary_source":"","published":"2026-09-25T22:10:39.706Z"},{"affected":"< 26.6.0","affected_versions_present":true,"cve_id":"CVE-2026-49229","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49229","fixed":"26.6.0.","last_modified":"2026-07-09T13:56:02.796Z","patch_url":"https://github.com/actualbudget/actual/security/advisories/GHSA-cq9c-6w48-qmfg","primary_source":"","published":"2026-07-07T20:59:34.173Z"},{"affected":"< 26.6.0","affected_versions_present":true,"cve_id":"CVE-2026-50179","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50179","fixed":"26.6.0.","last_modified":"2026-07-09T14:42:17.117Z","patch_url":"https://github.com/actualbudget/actual/security/advisories/GHSA-xqjm-27pc-rvwm","primary_source":"","published":"2026-07-07T20:58:16.074Z"},{"affected":"< 26.6.0","affected_versions_present":true,"cve_id":"CVE-2026-46700","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46700","fixed":"26.6.0.","last_modified":"2026-07-08T14:43:18.586Z","patch_url":"https://github.com/actualbudget/actual/security/advisories/GHSA-3f62-qv96-4p78","primary_source":"","published":"2026-07-07T20:56:39.203Z"},{"affected":"< 26.6.0","affected_versions_present":true,"cve_id":"CVE-2026-46672","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46672","fixed":"26.6.0.","last_modified":"2026-07-08T13:00:02.162Z","patch_url":"https://github.com/actualbudget/actual/security/advisories/GHSA-7gh7-258j-4mpq","primary_source":"","published":"2026-07-07T20:55:02.846Z"},{"affected":"< 26.7.0","affected_versions_present":true,"cve_id":"CVE-2026-50007","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50007","fixed":"26.7.0.","last_modified":"2026-07-08T14:02:20.277Z","patch_url":"https://github.com/actualbudget/actual/security/advisories/GHSA-23vm-ffgg-qvjr","primary_source":"","published":"2026-07-07T20:53:21.457Z"},{"affected":"< 26.5.0","affected_versions_present":true,"cve_id":"CVE-2026-43872","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-43872","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-15T19:28:23.704Z","patch_url":"","primary_source":"","published":"2026-06-12T19:05:42.615Z"},{"affected":"< 26.5.0","affected_versions_present":true,"cve_id":"CVE-2026-42890","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42890","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-12T20:04:10.446Z","patch_url":"","primary_source":"","published":"2026-06-12T18:58:42.239Z"},{"affected":"< 26.5.0","affected_versions_present":true,"cve_id":"CVE-2026-42604","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42604","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-15T13:10:30.083Z","patch_url":"","primary_source":"","published":"2026-06-12T18:42:38.346Z"},{"affected":"< 26.4.0","affected_versions_present":true,"cve_id":"CVE-2026-33318","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33318","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-25T01:44:08.129Z","patch_url":"https://github.com/actualbudget/actual/security/advisories/GHSA-prp4-2f49-fcgp","primary_source":"","published":"2026-04-24T02:13:47.200Z"},{"affected":"< 26.2.1","affected_versions_present":true,"cve_id":"CVE-2026-27638","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27638","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-02T20:48:53.277Z","patch_url":"https://github.com/actualbudget/actual/commit/9966c024cb75f57943193cac8e42f401efed9d08","primary_source":"","published":"2026-02-26T22:14:21.481Z"},{"affected":"< 26.2.1","affected_versions_present":true,"cve_id":"CVE-2026-27584","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27584","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-27T20:48:57.689Z","patch_url":"https://github.com/actualbudget/actual/commit/ea937d100956ca56689ff852d99c28589e2a7d88","primary_source":"","published":"2026-02-24T14:59:21.175Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"actualbudget"}}
