PT-2026-57323 · Grist · Grist
CVE-2026-55664
·
Published
2026-07-10
·
Updated
2026-07-10
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Grist versions prior to 1.7.15
Description
The 'GET /forms' endpoint fails to apply document access rules when reading table and column metadata and does not verify if the requested section is a form. This allows a user with partial read access, including public access to a publicly viewable document, to request metadata for any widget and reveal the table and column structure that should be hidden by access rules, regardless of whether the document contains forms.
Recommendations
Update to version 1.7.15.
Exploit
Fix
Information Disclosure
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Grist