PT-2026-57323 · Grist · Grist

CVE-2026-55664

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grist versions prior to 1.7.15
Description The 'GET /forms' endpoint fails to apply document access rules when reading table and column metadata and does not verify if the requested section is a form. This allows a user with partial read access, including public access to a publicly viewable document, to request metadata for any widget and reveal the table and column structure that should be hidden by access rules, regardless of whether the document contains forms.
Recommendations Update to version 1.7.15.

Exploit

Fix

Information Disclosure

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55664
GHSA-W2HC-W6CG-XVH9

Affected Products

Grist