CVE-2024-56358 — grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have their account compromised, because JavaScript in an SVG file would be evaluated — CVE Database · The Intelligence Room