CVE-2026-24002Disclosure(getgrist / grist-core)

LOWCVSS 9.6 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch getgrist grist-core systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formulas in a sandbox, for cases where the user may be working with untrusted spreadsheets. One such method runs them in pyodide, but pyodide on node does not have a useful sandbox barrier. If a user of Grist sets `GRIST_SANDBOX_FLAVOR` to `pyodide` and opens a malicious document, that document could run arbitrary processes on the server hosting Grist. The problem has been addressed in Grist version 1.7.9 and up, by running pyodide under deno. As a workaround, a user can use the gvisor-based sandbox by setting `GRIST_SANDBOX_FLAVOR` to `gvisor`.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • grist-core

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 11 signals
  • Disclosure: 9 classified signals
  • Peaked 4d ago at 4 mentions (2026-01-29); latest day: 1
  • 12 total mentions across 7 days

Affected systems

Vendors
Products
grist-core

Deep dive

Activity timeline12 mentions / 7d
01234Mentions · 2026-01-27: 1Mentions · 2026-01-28: 2Mentions · 2026-01-29: 4Mentions · 2026-02-02: 1Mentions · 2026-02-05: 1Mentions · 2026-02-06: 2Mentions · 2026-03-30: 1PoC Mentioned / Linked · 2026-01-28: 1PoC Mentioned / Linked · 2026-02-05: 1PoC Mentioned / Linked · 2026-03-30: 1Patch / Workaround · 2026-01-27: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-01-29: 2Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-02-06: 1Technical Details · 2026-01-27: 1Technical Details · 2026-01-28: 2Technical Details · 2026-01-29: 4Technical Details · 2026-02-02: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-06: 1Technical Details · 2026-03-30: 101-2701-2801-2902-0202-0502-0603-30
Signal classification2 categories
Disclosure
975.0%
Patch
325.0%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-01-271
Patch1
2026-01-282
Disclosure1Patch1
2026-01-294
Disclosure3Patch1
2026-02-021
Disclosure1
2026-02-051
Disclosure1
2026-02-062
Disclosure2
2026-03-301
Disclosure1
Full discourse12 posts
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-24002 (CVSS score: 9.1): Critical Grist-Core Vulnerability Allows RCE Attacks via Spreadsheet Formulas. 🧐Deep Dive :https://www.cyera.com/research-labs/cellbreak-grists-pyodide-sandbox-escape-and-the-data-at-risk-blast-radius 📊 2.8K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Grist%22 👇Query HUNTER : http://product.name="Grist" 📰Refer:https://thehackernews.com/2026/01/critical-grist-core-vulnerability.html https://github.com/gristlabs/grist-core/security/advisories/GHSA-7xvx-8pf2-pv5g #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces the new CVE‑2026‑24002, a critical RCE flaw in Grist‑Core enabling attacks through spreadsheet formulas, and references detailed research and advisories, but does not mention active exploitation, PoC, or patches.

    0802683.6K
    25.4K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    プログラム可能な表計算ソフトGrist-Coreに重大(Critical)な脆弱性。CVE-2026-24002はCVSSスコア9.1のPyodideサンドボックスエスケープ。遠隔コード実行可能。修正版提供済み。 https://securityonline.info/cve-2026-24002-critical-sandbox-escape-turns-grist-spreadsheets-into-rce-weapons/

    Post summary

    The post highlights a critical Grist‑Core vulnerability (CVE‑2026‑24002) with a CVSS 9.1 sandbox escape enabling RCE, and confirms that a patch has already been released.

    01041987
    7.2K followersView on X
  • Mr. OS@ksg93rd
    Disclosure

    #exploit #AppSec 1⃣. CVE-2025-67813: RCE via Quest Desktop Authority Named Pipe https://www.netspi.com/blog/technical-blog/adversary-simulation/pipe-dreams-remote-code-execution-via-quest-desktop-authority-named-pipe // A vulnerability in Quest Desktop Authority allows authenticated users to remotely execute code and perform malicious operations via a named pipe, which can be mitigated by patches, firewalls, or disabling the service 2⃣. CVE-2026-24002: RCE sandbox escape in Grist‑Core https://www.cyera.com/research-labs/cellbreak-grists-pyodide-sandbox-escape-and-the-data-at-risk-blast-radius // One malicious formula can turn a spreadsheet into a RCE beachhead... 3⃣. CVE-2025-49825: Teleport remote authentication bypass https://blog.offensive.af/posts/exploiting-cve-2025-49825 // CVE-2025-49825 is a critical Teleport vulnerability allowing attackers to bypass authentication and potentially gain root access via nested SSH certificates if unpatched

    Post summary

    The post discloses three new vulnerabilities (RCE and authentication bypass), provides technical details and mitigation steps, and links to external PoCs.

    10011255
    3.1K followersView on X
  • White Rabbitx@TheRabbitPy
    Disclosure

    CVE‑2026‑24002 “Cellbreak” in Grist‑Core lets attackers escape the Pyodide sandbox via malicious spreadsheet formulas, turning a programmable spreadsheet platform into an RCE‑over‑web open‑bar. https://www.rescana.com/post/cve-2026-24002-critical-grist-core-vulnerability-enables-remote-code-execution-via-spreadsheet-form

    Post summary

    The post discloses a critical RCE vulnerability (CVE‑2026‑24002) in Grist‑Core, enabling sandbox escape through malicious spreadsheet formulas.

    1000048
    521 followersView on X
  • transilienceai@transilienceai
    Disclosure

    🚨 Grist-Core [—] Feb 06, 2026 Comprehensive security advisory on the 'Cellbreak' vulnerability (CVE-2026-24002) in Grist-Core, covering risk, impacts, technical analysis, and mitigation. Checkout our Threat Intelligence Platform: https://threatintel.transilience.cloud... https://t.co/ilbNgR4Jkc

    Post summary

    A comprehensive advisory on CVE-2026-24002, covering risk, impacts, technical analysis, and mitigation steps, was released by Grist-Core.

    0000053
    316 followersView on X
  • Glitch News@glitch4techs
    Disclosure

    خطر RCE يضرب Grist-Core! 🚨 تحذير أمني عاجل! ثغرة "Cellbreak" (CVE-2026-24002, CVSS 9.1) تهدد Grist-Core (مفتوح المصدر). صيغة خبيثة تسبب تنفيذ تعليمات عن بعد (RCE). هل تستخدم Grist-Core؟ ما خطتك؟ #أمن_سيبراني #RCE #GristCore 🔗 المصدر: https://thehackernews.com/2026/01/critical-grist-core-vulnerability.html

    Post summary

    A new CVE‑2026‑24002 RCE vulnerability with CVSS 9.1 has been disclosed for Grist‑Core; the post warns users but does not provide PoC, exploit code, or patch information.

    0000099
    19 followersView on X
  • transilienceai@transilienceai
    Disclosure

    🚨 Grist-Core [—] Feb 02, 2026 Comprehensive Security Advisory: Critical RCE Vulnerability (CVE-2026-24002 'Cellbreak') in Grist-Core Spreadsheet Platform Checkout our Threat Intelligence Platform: https://threatintel.transilience.cloud https://threatintel.transilience.cloud https://t.co/ZDrE7oZzVG

    Post summary

    A comprehensive advisory discloses a critical RCE vulnerability (CVE‑2026‑24002) in Grist‑Core’s spreadsheet platform, but no PoC, exploit code, active exploitation evidence, or patch details are provided.

    0000051
    317 followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    CVE-2026-24002: Critical Sandbox Escape Turns Grist Spreadsheets into RCE Weapons https://securityonline.info/cve-2026-24002-critical-sandbox-escape-turns-grist-spreadsheets-into-rce-weapons/

    Post summary

    The article announces CVE‑2026‑24002, a critical sandbox escape that turns Grist spreadsheets into remote code execution vectors, providing basic technical details but no information on PoC, exploitation, or patches.

    0000050
    72 followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    CVE-2026-24002: Critical Sandbox Escape Turns Grist Spreadsheets into RCE Weapons https://securityonline.info/cve-2026-24002-critical-sandbox-escape-turns-grist-spreadsheets-into-rce-weapons/

    Post summary

    A newly disclosed CVE-2026-24002 describes a critical sandbox escape in Grist Spreadsheets that enables remote code execution. No PoC, exploit, or patch details are mentioned in the snippet.

    0000056
    298 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 “Cellbreak” Critical Flaw Turns Grist Spreadsheets into RCE Beachheads (CVE-2026-24002) A critical Pyodide sandbox-escape in Grist-Core (CVE-2026-24002, CVSS 9.1) lets malicious spreadsheet formulas execute OS commands or host-runtime JavaScript, enabling filesystem access and potential theft of secrets like DB credentials and API keys. Fixed in Grist 1.7.9; avoid using GRIST_PYODIDE_SKIP_DENO when untrusted formulas are possible. 🎯 Target: Global/Organizations using Grist-Core #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.scworld.com/brief/critical-cellbreak-vulnerability-in-grist-core-allows-remote-code-execution

    Post summary

    The piece announces a critical remote‑code‑execution flaw (CVE‑2026‑24002) in Grist Core, details its severity (CVSS 9.1), and notes the fix in version 1.7.9 with a recommended workaround.

    0000061
    196 followersView on X
  • sctocs@sctocs25
    Patch

    Critical Grist-Core vulnerability (CVE-2026-24002) allows RCE via malicious spreadsheet formulas — update to v1.7.9 now! https://sctocs.com/critical-grist-core-vulnerability-rce-spreadsheet-formulas/

    Post summary

    CVE‑2026‑24002 is a critical RCE vulnerability in Grist‑Core, exploitable via malicious spreadsheet formulas. A patch (v1.7.9) is available and has been released.

    0000039
    4 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 “Cellbreak” in Grist-Core: Pyodide Sandbox Escape Lets Malicious Spreadsheets Trigger Server RCE (CVE-2026-24002) Cyera and Grist maintainers warn that if Grist-Core is configured to run formulas in the Pyodide sandbox (GRIST_SANDBOX_FLAVOR=pyodide), a crafted spreadsheet/formula can break out and execute arbitrary processes on the host server. Patch/upgrade immediately and avoid Pyodide for untrusted documents, since this turns a shared spreadsheet into a remote code execution foothold. 🎯 Target: Global/Self-Hosted Grist-Core (Spreadsheet Platforms) #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://www.infosecurity-magazine.com/news/pyodide-sandbox-escape-rce-grist/

    Post summary

    The post discloses that Grist‑Core’s Pyodide sandbox can be escaped to enable server‑side RCE, and it recommends immediate patching or disabling of the sandbox for untrusted documents.

    0000048
    196 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetgristgrist-core---

Explore more