Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Unmasking new TOAD attacks hidden in legitimate infrastructure

Fortinet patches CVE-2026-24858 after active FortiOS SSO exploit detected

Anduril has invented a novel drone flying contest where work is the prize

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Critical vulnerability in Grist-Core allows RCE attacks via spreadsheet formulas
Identity

Critical vulnerability in Grist-Core allows RCE attacks via spreadsheet formulas

userBy userJanuary 27, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananJanuary 27, 2026Vulnerability / Cloud Security

A critical security flaw has been disclosed in Grist‑Core, an open source self-hosted version of the Grist relational spreadsheet database, that could allow remote code execution.

This vulnerability is tracked as CVE-2026-24002 (CVSS score: 9.1) and codenamed “Cellbreak” by Cyera Research Labs.

“A malicious formula could turn a spreadsheet into a remote code execution (RCE) beachhead,” said security researcher Vladimir Tokarev, who discovered the flaw. “This sandbox escape allows formula authors to execute OS commands or execute host runtime JavaScript, collapsing the boundaries between ‘cell logic’ and host execution.”

cyber security

Cellbreak is classified as a case of Pyodide sandbox escape. This is the same type of vulnerability that also recently affected n8n (CVE-2025-68668, CVSS score: 9.9, aka N8scape). This vulnerability was resolved in version 1.7.9, released on January 9, 2026.

“A security review identified a vulnerability in the ‘pyodide’ sandboxing method available in Grist,” project administrators said. “You can check to see if you’re affected in the sandbox section of your instance’s admin panel. If you see ‘gvisor’ there, you’re not affected. If you see “pyodide”, it is important to update to this version of Grist or later.

In a nutshell, the root of this problem lies in Grist’s execution of Python expressions. This allows untrusted expressions to be executed within Pyodide. Pyodide is a Python distribution that allows you to run regular Python code directly in your web browser within the WebAssembly (WASM) sandbox.

The idea behind this thought process is to ensure that Python-style code runs in an isolated environment, but the fact that Grist uses a blocklist-style approach makes it possible to escape the sandbox and ultimately execute commands on the underlying host.

“The sandbox design allows traversal of Python’s class hierarchy and makes ctypes available. This provides access to Emscripten runtime functions that are not accessible from formula cells,” Tokarev explained. “This combination allows host command execution and JavaScript execution in the host runtime, with practical consequences such as file system access and security disclosure.”

According to Grist, if a user opens a malicious document with GRIST_SANDBOX_FLAVOR set to Pyodide, that document can be used to run arbitrary processes on the server hosting Grist. An attacker with this ability to execute commands or JavaScript via an expression can use this behavior to access database credentials and API keys, read sensitive files, and provide opportunities for lateral movement.

cyber security

Grist addressed this issue by moving execution of Pyodide expressions under the Deno JavaScript runtime by default. Note, however, that the risk resurfaces if the operator explicitly chooses to set GRIST_PYODIDE_SKIP_DENO to the value ‘1’. This setting should be avoided in scenarios where untrusted or semi-reliable expressions may be executed.

To reduce potential risks, users are encouraged to update to the latest version as soon as possible. To temporarily alleviate this issue, we recommend setting the GRIST_SANDBOX_FLAVOR environment variable to ‘gvisor’.

“This reflects a systemic risk seen in other automation platforms: a single execution surface with privileged access can disrupt an organization’s trust boundaries in the event of a sandbox failure,” Tokarev said.

“If formula execution relies on a permissive sandbox, a single escape can turn “data logic” into “host execution.” Grist-Core’s findings demonstrate why sandboxing needs to be feature-based and defense-in-depth, rather than a brittle blocklist. The cost of failure is not just a bug, but a data plane compromise. ”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHistoric deal signed to advance UK and European clean energy security
Next Article MareNostrum 5 Major Upgrade Powers EU AI Supercomputing
user
  • Website

Related Posts

Unmasking new TOAD attacks hidden in legitimate infrastructure

January 28, 2026

Fortinet patches CVE-2026-24858 after active FortiOS SSO exploit detected

January 28, 2026

WhatsApp deploys lockdown-style security mode to protect targeted users from spyware

January 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Unmasking new TOAD attacks hidden in legitimate infrastructure

Fortinet patches CVE-2026-24858 after active FortiOS SSO exploit detected

Anduril has invented a novel drone flying contest where work is the prize

Bluesky previews 2026 roadmap: Discover feed, real-time features, and more improvements

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.