Executive brief
Grist is a spreadsheet and database tool used for organizing and analyzing data. A security flaw allowed users with limited access to a document to bypass security rules and view the underlying structure of tables and columns they should not be able to see. While this does not expose the actual data within the cells, it reveals how the database is organized, which could expose sensitive business logic or internal naming conventions.
Technical details
An improper authorization vulnerability exists in the GET /forms endpoint of Grist. The endpoint was found to read table and column metadata directly from the document data instead of using the access-rule-aware 'fetchMetaTables' function. Additionally, the endpoint failed to verify if the requested section was actually a form. An attacker with at least partial read access (including public access) can exploit this by providing a section ID for any widget to retrieve metadata that should be restricted by access rules. This results in the exposure of table and column structures (CWE-200, CWE-285). The issue is resolved in version 1.7.15 by enforcing access-rule checks and validating that the requested section is a form.
Affected products
- Grist Labs Grist < 1.7.15
Timeline
- 2026-06-10: patched: Version 1.7.15 released
- 2026-06-19: advisory: GitHub Security Advisory GHSA-w2hc-w6cg-xvh9 published
- 2026-07-10: disclosed: CVE-2026-55664 published to NVD