logo

CVE-2026-24002: Critical Sandbox Escape Turns Grist Spreadsheets into RCE Weapons

ID: 2d03fe39-2973-51cb-9809-23683e12c47d

STIX ID: report--2d03fe39-2973-51cb-9809-23683e12c47d

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-29

Date Updated: 2026-04-23

Author: Ddos

...
...

A Cyera Research Labs report identifies CVE-2026-24002, a critical Grist vulnerability (CVSS 9.1) that enables Pyodide sandbox escapes and full RCE via normal spreadsheet formulas by abusing legitimate data paths; researchers detail three sandbox-escape techniques and Grist patched the issue by running Pyodide formulas under Deno (upgrade to 1.7.9+ and do not set GRIST_PYODIDE_SKIP_DENO=1).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.