PT-2026-57324 · Grist · Grist

CVE-2026-55665

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grist versions prior to 1.7.15
Description Two cross-site scripting issues exist where attacker-controlled values reach a link's href without scheme validation, allowing a javascript URL to execute in a victim's origin upon a single click. On the account-selection page, the endpoint '/welcome/select-account' uses the next query parameter as the link target for account buttons. Additionally, in document tours, the Link URL column of the GristDocTour table is rendered as a clickable button; a document editor can store a javascript URL here that executes when another user clicks the tour link. Since the script runs within the victim's authenticated session, it can call APIs to read or modify data and change sharing settings, potentially allowing a document editor to escalate privileges to owner-level access.
Recommendations Update to version 1.7.15.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55665
GHSA-7F6V-VGHQ-34XQ

Affected Products

Grist