← Πίσω στην αναζήτηση CVE

CVE-2026-55665

Grist

Περιγραφή

Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, Grist contained two cross-site scripting vulnerabilities where an attacker-controlled value reached a link-s href without scheme validation, so a javascript URL could run in a victim-s Grist origin on a single click. On the account-selection page, /welcome/select-account used its next query parameter as the account buttons- link target. In document tours, the GristDocTour table-s Link_URL column became a clickable button, allowing an editor of a shared document to store a javascript URL there that ran when another user opened the document and clicked the tour link. Because the script runs in the victim-s authenticated session, it can call Grist APIs as the victim, reading or modifying data and changing sharing settings and access rules. A document editor could therefore escalate to owner-level access. This issue is fixed in version 1.7.15.

CVSS 8.5EPSS 0.322%Κίνδυνος 0.87
Προβολή πηγής
Δημοσίευση
2026-07-10 21:16:56
Επηρεαζόμενες εκδόσεις
<1.7.15
Τύπος
Εφαρμογή ιστού
Διάνυσμα
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X