gristlabs grist-core是gristlabs公司的一款现代关系电子表格软件。 gristlabs grist-core 1.7.15之前版本存在安全漏洞,该漏洞源于服务器渲染页面未完全转义用户控制的值,容易受到跨站脚本攻击,文档编辑者可能因此提升至所有者级权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| gristlabs | grist-core | < 1.7.15 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gristlabs | grist-core | < 1.7.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55664 | 4.3 MEDIUM | Grist: Insufficient access control in the /forms endpoint exposes table metadata |
| CVE-2026-55665 | DOM-based XSS in Grist via unsanitized links, enabling privilege escalation |
No comments yet