Skip to content
Critical RCE Vulnerability Discovered in Grist-Core Spreadsheet Platform

Critical RCE Vulnerability Discovered in Grist-Core Spreadsheet Platform

First seen 28 Jan 2026, 15:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A critical vulnerability, CVE-2026-24002, known as 'Cellbreak', has been identified in Grist-Core, a widely used programmable spreadsheet platform. This flaw allows remote code execution (RCE) via malicious spreadsheet formulas, affecting both SaaS and self-hosted deployments. The vulnerability has a CVSS score of 9.1 and has been patched following coordinated disclosure with the Grist-Core security team.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (3)

Following this threat?

Track CVE-2026-24002 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed