CVE-2026-55665
gristlabs grist-core
Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, Grist contained two cross-site scripting vulnerabilities where an attacker-controlled value reached a link's href without scheme validation, so a javascript URL could run in a victim's Grist origin on a single click. On the account-selection page, /welcome/select-account used its next query parameter as the account buttons' link target. In document tours, the GristDocTour table's Link_URL column became a clickable button, allowing an editor of a shared document to store a javascript URL there that ran when...
- CVSS
- 8.5
- EPSS
- 0.32% 24.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.11