CVE-2026-24002: Critical Sandbox Escape Turns Grist Spreadsheets into RCE Weapons
ID: 2d03fe39-2973-51cb-9809-23683e12c47d
STIX ID: report--2d03fe39-2973-51cb-9809-23683e12c47d
Feed Name: securityonline.info
Threat Score
A Cyera Research Labs report identifies CVE-2026-24002, a critical Grist vulnerability (CVSS 9.1) that enables Pyodide sandbox escapes and full RCE via normal spreadsheet formulas by abusing legitimate data paths; researchers detail three sandbox-escape techniques and Grist patched the issue by running Pyodide formulas under Deno (upgrade to 1.7.9+ and do not set GRIST_PYODIDE_SKIP_DENO=1).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
