PT-2025-46917 · Unknown · Grist-Core

Published

2025-11-13

·

Updated

2025-11-14

·

CVE-2025-64753

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions grist-core versions prior to 1.7.7
Description grist-core is a spreadsheet hosting server. A user with limited read access to a document could access endpoints that reveal hashes for different versions of the document and obtain a complete list of changes between versions, including data they were not authorized to view. This issue was addressed by restricting access to the /compare endpoint to users with full read access. The vulnerable endpoint is /compare. The affected data includes cells, columns, and tables. A workaround involves removing sensitive document history using the /states/remove endpoint, or blocking the /compare endpoint.
Recommendations Update to version 1.7.7 or later. As a workaround, remove sensitive document history using the /states/remove endpoint. Block the /compare endpoint.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-64753
GHSA-3V78-CW58-V685

Affected Products

Grist-Core