PT-2026-57322 · Grist · Grist

CVE-2026-55659

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Grist versions prior to 1.7.15
Description Several server-rendered pages embed user-controlled values into the page and inline scripts without full escaping, leading to cross-site scripting (XSS). On the main application page, a document editor can set a document name or description that is rendered for other users. Additionally, on the OAuth2 end-of-flow page, the openerOrigin request parameter is reflected back into the served page. An injected script executes within the victim's origin and can utilize the authenticated session to read or modify data, change sharing settings, and alter access rules, potentially allowing a document editor to escalate to owner-level access.
Recommendations Update Grist to version 1.7.15.

Exploit

Fix

Improper Encoding or Escaping of Output

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55659
GHSA-6QRQ-H2H6-CW54

Affected Products

Grist