Junglewise Threat Intelligence

CVE-2026-12188: Grit42 Grit SQL injection in GritEntityController CSV export

CVE-2026-12188 · Severity: medium · CVSS 6.3 · Published 2026-06-14

Executive brief

Grit42 Grit, a platform used for managing scientific data, contains a security flaw in its CSV export feature. An authorized user can exploit this vulnerability to run unauthorized database commands, potentially leading to the exposure of sensitive research data or disruption of the system. This could impact the integrity of scientific records and overall operational reliability.

Technical details

A SQL injection vulnerability exists in Grit42 Grit versions up to 0.11.0 within the GritEntityController component. The flaw is located in the backend controller logic (grit_entity_controller.rb) responsible for handling CSV exports. An attacker with low-level authenticated access can manipulate input parameters to execute arbitrary SQL queries against the underlying database. This can result in unauthorized data retrieval, modification, or deletion. The vulnerability is exploitable over the network, and public exploit details have been disclosed. No official patch has been confirmed by the vendor at the time of disclosure.

Affected products

  • Grit42 Grit up to 0.11.0

Timeline

  • 2026-06-14: disclosed: Vulnerability disclosed via VulDB and NVD
  • 2026-06-14: advisory: Public advisory released by Thoropass research program

References

Related threats