PT-2025-46916 · Unknown · Grist-Core

CVE-2025-64752

·

Published

2025-11-13

·

Updated

2025-11-14

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions grist-core versions prior to 1.7.7
Description grist-core is a spreadsheet hosting server. A user with access to any document on a Grist installation can use a feature for fetching from a URL that is executed on the server. The privileged network access of server-side requests could offer opportunities for attack escalation. As a workaround, avoid making http/https endpoints available to an instance running Grist that expose credentials or operate without credentials.
Recommendations Update to version 1.7.7 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64752
GHSA-QH95-2QV8-PQX3

Affected Products

Grist-Core