logo

Pyodide Sandbox Escape Enables Remote Code Execution in Grist-Core

ID: beb53f7a-6679-5790-977d-0826866b9002

STIX ID: report--beb53f7a-6679-5790-977d-0826866b9002

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-01-27

Date Updated: 2026-04-22

...
...

A critical sandbox-escape vulnerability (CVSS 9.1) in Grist-Core allowed a spreadsheet formula to break out of the Pyodide WebAssembly sandbox and execute host OS commands or JavaScript, exposing environment variables, credentials and enabling potential lateral movement. Cyera Research Labs disclosed the issue and Grist patched it in version 1.7.9 by running Pyodide under Deno with a permissions-based isolation layer; operators are advised to upgrade and treat formula execution as a privileged capability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.