logo

Cellbreak: Grist’s Pyodide Sandbox Escape and the Data-at-Risk Blast Radius

ID: ce5accb2-4572-5b4c-8690-3f91f8386f01

STIX ID: report--ce5accb2-4572-5b4c-8690-3f91f8386f01

Feed Name: Cyera Research Labs

Threat Score
78/100

Date Published: 2026-01-26

Date Updated: 2026-04-27

...
...

**Executive Summary:** Cyera Research Labs discovered a critical Pyodide sandbox escape in Grist‑Core that allows malicious spreadsheet formulas to achieve remote code execution (CVSS 9.1) via multiple reliable paths (builtins traversal to os.system, ctypes.CDLL(None).system, and emscripten_run_script_string); Grist released a patch (Grist 1.7.9) running Pyodide under Deno by default, but the risk persists if operators bypass Deno (GRIST_PYODIDE_SKIP_DENO=1).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.