Critical RCE Vulnerability Discovered in Grist-Core Spreadsheet Platform

Critical RCE Vulnerability Discovered in Grist-Core Spreadsheet Platform

First seen 28 Jan 2026, 15:08 UTC Infosecurity-MagazineRescanaLinkedin 78.9

Article Content

Browse articles
ThreatCluster

A critical vulnerability, CVE-2026-24002, known as 'Cellbreak', has been identified in Grist-Core, a widely used programmable spreadsheet platform. This flaw allows remote code execution (RCE) via malicious spreadsheet formulas, affecting both SaaS and self-hosted deployments. The vulnerability has a CVSS score of 9.1 and has been patched following coordinated disclosure with the Grist-Core security team.