‘GrafanaGhost’ bypasses Grafana’s AI defenses without leaving a trace
ID: e41b337c-0e16-5a0a-a073-42c126569389
STIX ID: report--e41b337c-0e16-5a0a-a073-42c126569389
Feed Name: CyberScoop
Threat Score
Noma Security disclosed "GrafanaGhost," a high-impact vulnerability chain in Grafana that can use indirect prompt injection and a misinterpreted domain validation check to cause the platform's AI components to fetch attacker-controlled resources carrying sensitive data; Grafana released a patch after validation but disputes the claim the issue is truly zero-click or silently exploited, and no in-the-wild exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
