CVE-2026-55659
gristlabs grist-core
Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages embedded user-controlled values into the page and into inline scripts without fully escaping them, allowing cross-site scripting. On the main application page, a document's name or description, set by a document editor, is rendered into the page that other users load when opening the document. On the OAuth2 end-of-flow page, the openerOrigin request parameter was reflected back into the served page. Injected script runs in the victim's Grist origin and can act through the...
- CVSS
- 7.7
- EPSS
- 0.27% 19.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.11