PT-2026-57324 · Grist · Grist
CVE-2026-55665
·
Published
2026-07-10
·
Updated
2026-07-10
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grist versions prior to 1.7.15
Description
Two cross-site scripting issues exist where attacker-controlled values reach a link's href without scheme validation, allowing a javascript URL to execute in a victim's origin upon a single click. On the account-selection page, the endpoint '/welcome/select-account' uses the
next query parameter as the link target for account buttons. Additionally, in document tours, the Link URL column of the GristDocTour table is rendered as a clickable button; a document editor can store a javascript URL here that executes when another user clicks the tour link. Since the script runs within the victim's authenticated session, it can call APIs to read or modify data and change sharing settings, potentially allowing a document editor to escalate privileges to owner-level access.Recommendations
Update to version 1.7.15.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grist