CVE-2026-24002
- EPSS 0.02%
- Veröffentlicht 22.01.2026 02:26:28
- Zuletzt bearbeitet 17.02.2026 17:59:16
Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formulas in a sandbox, for cases where the user may be working with untrusted spreadsheets. One such method runs them in pyodide, but p...
CVE-2025-64753
- EPSS 0.04%
- Veröffentlicht 13.11.2025 21:46:00
- Zuletzt bearbeitet 20.11.2025 21:11:25
grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document could still access endpoints listing hashes for versions of that document and receive a full list of changes between versions, even...
CVE-2025-64752
- EPSS 0.05%
- Veröffentlicht 13.11.2025 21:43:57
- Zuletzt bearbeitet 26.11.2025 16:19:34
grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with access to any document on a Grist installation can use a feature for fetching from a URL that is executed on the server. The privileged network access of server-side requ...
CVE-2024-56357
- EPSS 0.68%
- Veröffentlicht 20.12.2024 21:15:10
- Zuletzt bearbeitet 12.03.2025 17:36:08
grist-core is a spreadsheet hosting server. A user visiting a malicious document or submitting a malicious form could have their account compromised, because it was possible to use the `javascript:` scheme with custom widget URLs and form redirect UR...
CVE-2024-56358
- EPSS 0.68%
- Veröffentlicht 20.12.2024 21:15:10
- Zuletzt bearbeitet 12.03.2025 17:33:10
grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have their account compromised, because JavaScript in an SVG file would be evaluated in the context of their current page. This issue ...
CVE-2024-56359
- EPSS 0.62%
- Veröffentlicht 20.12.2024 21:15:10
- Zuletzt bearbeitet 12.03.2025 17:32:22
grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink cell using a control modifier (meaning for example Ctrl+click) could have their account compromised, since the link could use the j...