grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document could still access endpoints listing hashes for versions of that document and receive a full list of changes between versions, even if those changes contained cells, columns, or tables to which the user was not supposed to have read access. This was fixed in version 1.7.7 by restricting the `/compare` endpoint to users with full read access. As a workaround, remove sensitive document history using the `/states/remove` endpoint. Another possibility is to block the `/compare` endpoint.
History

Thu, 20 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:getgrist:grist-core:*:*:*:*:*:*:*:*

Fri, 14 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Nov 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Getgrist
Getgrist grist-core
Vendors & Products Getgrist
Getgrist grist-core

Thu, 13 Nov 2025 22:00:00 +0000

Type Values Removed Values Added
Description grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document could still access endpoints listing hashes for versions of that document and receive a full list of changes between versions, even if those changes contained cells, columns, or tables to which the user was not supposed to have read access. This was fixed in version 1.7.7 by restricting the `/compare` endpoint to users with full read access. As a workaround, remove sensitive document history using the `/states/remove` endpoint. Another possibility is to block the `/compare` endpoint.
Title grist-core has insufficient access control in endpoints for comparisons between documents and versions
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-13T21:46:00.508Z

Updated: 2025-11-14T16:17:23.927Z

Reserved: 2025-11-10T22:29:34.874Z

Link: CVE-2025-64753

cve-icon Vulnrichment

Updated: 2025-11-14T16:16:34.487Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-13T22:15:52.750

Modified: 2025-11-20T21:11:25.813

Link: CVE-2025-64753

cve-icon Redhat

No data.