CVE-2025-64752 - CVE House
Back to Database
Status published Medium CVE-2025-64752

grist-core has path to server-side requests via websocket

Vulnerability Description

grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with access to any document on a Grist installation can use a feature for fetching from a URL that is executed on the server. The privileged network access of server-side requests could offer opportunities for attack escalation. This issue is fixed in version 1.7.7. The mitigation was to use the proxy for untrusted fetches intended for such purposes. As a workaround, avoid making http/https endpoints available to an instance running Grist that expose credentials or operate without credentials.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64752

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

grist-core
Vulnerable Versions:
< 1.7.7

Timeline

Official Publish: November 13th, 2025
Last Modified: November 14th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Weaknesses (CWE)