A critical security vulnerability in Grist-Core, an open-source, self-hosted version of the relational spreadsheet-database Grist, could lead to remote code execution.

The vulnerability, tracked as CVE-2026-24002 (CVSS score: 9.1), has been codenamed “Cellbreak” by Cyera Research Labs.
“A malicious person can turn a spreadsheet into a Remote Code Execution (RCE) beachhead,” said security researcher Vladimir Tokarev, who discovered the vulnerability. “This sandbox escape allows a formula author to execute operating system commands or run host-runtime JavaScript, breaking down the boundary between ‘cell logic’ and host execution.”
See also: 6,000 SmarterMail servers exposed to the internet and vulnerable to attacks
The Cellbreak vulnerability is categorized as a Pyodide sandbox escape, the same type of vulnerability that recently affected n8n (CVE-2025-68668, CVSS score: 9.9, also known as N8scape). The vulnerability has been addressed in version 1.7.9, released on January 9, 2026.
“A security review has identified a vulnerability in the 'pyodide' sandboxing method available on Grist,” the project maintainers said. “You can check if you are affected in the sandboxing section of your installation’s Admin Panel. If you see 'gvisor' there, then you are not affected. If you see 'pyodide', then it is important to update to this version of Grist or a later version.”

The issue is located in Python formula execution in Grist, which allows untrusted formulas to be executed within Pyodide, a Python distribution that allows regular Python code directly in a web browser, within the confines of a WebAssembly (WASM) sandbox.
While the idea behind this thought process is to ensure that Python formula code is executed in an isolated environment, the fact that Grist uses a blocklist-style approach makes it possible to escape the sandbox and ultimately achieve command execution on the underlying host.
See also: Vulnerabilities in npm and yarn platforms allow bypass of Shai-Hulud defenses
According to Grist, when a user has GRIST_SANDBOX_FLAVOR set in Pyodide and opens a malicious document, that document could be used to execute arbitrary processes on the server hosting Grist. Armed with this ability to execute commands or JavaScript via formulas, an attacker can leverage this behavior to gain access to database credentials and API keys, read sensitive files, and move laterally across the network.
Grist-Core: How the security problem is being addressed
Grist has addressed the issue by moving Pyodide formula execution under the Deno JavaScript runtime, by default. However, it is worth noting that the risk resurfaces if an administrator explicitly chooses to set GRIST_PYODIDE_SKIP_DENO to “1.” This setting should be avoided in scenarios where untrusted or semi-trusted formulas are likely to be executed.
Users are advised to update to the latest version as soon as possible to mitigate potential risks. To temporarily mitigate the issue, it is recommended to set the environment variable GRIST_SANDBOX_FLAVOR to “gvisor”.
See also: CISA: VMware vCenter vulnerability in KEV Catalog

“This reflects the systemic risk found in other automation platforms: a single execution surface with privileged access can break down an organization’s trust boundaries when its sandbox fails,” Tokarev said.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
“When formula execution relies on a permissive sandbox, a single escape can turn 'data logic' into 'host execution'. Grist-Core's findings show why sandboxing should be based on capabilities and defense in depth, not a fragile blocklist. The cost of failure is not just a bug – it's a data-level breach“.
