CVE-2026-57449 | actualbudget Actual up to 26.6.x CORS Proxy startsWith cross-domain policy (EUVD-2026-87369)

SecurityVulns

A vulnerability described as problematic has been identified in actualbudget Actual up to 26.6.x. Impacted is the function startsWith of the component CORS Proxy. Such manipulation leads to permissive cross-domain policy with untrusted domains.

This vulnerability is uniquely identified as CVE-2026-57449. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More