📦 Grist Core

by Getgrist

🔍 What is Grist Core?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-24002

CRITICAL CVSS 9.0 Jan 22, 2026

This vulnerability allows arbitrary code execution on Grist servers when using the pyodide sandbox flavor with untrusted spreadsheets. Attackers can run arbitrary processes on the server hosting Grist...

CVE-2024-56358

HIGH CVSS 8.1 Dec 20, 2024

This vulnerability in grist-core allows cross-site scripting (XSS) attacks via malicious SVG attachments. When a user previews an attachment containing JavaScript in an SVG file, the code executes in ...

CVE-2025-64752

MEDIUM CVSS 6.8 Nov 13, 2025

This vulnerability in grist-core allows authenticated users to perform server-side request forgery (SSRF) attacks. Any user with document access can exploit a URL fetching feature to make requests fro...

CVE-2025-64753

MEDIUM CVSS 5.3 Nov 13, 2025

This vulnerability in grist-core allows users with partial read access to documents to view sensitive document history and changes they shouldn't have access to. It affects all grist-core deployments ...