logo

A Vulnerability in Grafana Could Allow for Arbitrary Code Execution

ID: aed6ce75-8f41-57f1-8dad-4adc485b951a

STIX ID: report--aed6ce75-8f41-57f1-8dad-4adc485b951a

Feed Name: CISecurity.org Advisories

Threat Score
70/100

Date Published: 2025-06-17

Date Updated: 2026-04-27

...
...

A cross-site scripting vulnerability in Grafana (CVE-2025-4123) results from a combination of client path traversal and an open redirect, allowing attackers to redirect users to malicious frontend plugins that execute arbitrary JavaScript. The flaw does not require editor permissions and works with anonymous access; if the Grafana Image Renderer plugin is installed it can be escalated to a full read SSRF, potentially enabling plugin execution and user account takeover, including against local instances via crafted payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.