A Vulnerability in Grafana Could Allow for Arbitrary Code Execution
ID: aed6ce75-8f41-57f1-8dad-4adc485b951a
STIX ID: report--aed6ce75-8f41-57f1-8dad-4adc485b951a
Feed Name: CISecurity.org Advisories
A cross-site scripting vulnerability in Grafana (CVE-2025-4123) results from a combination of client path traversal and an open redirect, allowing attackers to redirect users to malicious frontend plugins that execute arbitrary JavaScript. The flaw does not require editor permissions and works with anonymous access; if the Grafana Image Renderer plugin is installed it can be escalated to a full read SSRF, potentially enabling plugin execution and user account takeover, including against local instances via crafted payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
