PT-2025-46916 · Unknown · Grist-Core
Published
2025-11-13
·
Updated
2025-11-14
·
CVE-2025-64752
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
grist-core versions prior to 1.7.7
Description
grist-core is a spreadsheet hosting server. A user with access to any document on a Grist installation can use a feature for fetching from a URL that is executed on the server. The privileged network access of server-side requests could offer opportunities for attack escalation. As a workaround, avoid making http/https endpoints available to an instance running Grist that expose credentials or operate without credentials.
Recommendations
Update to version 1.7.7 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grist-Core