Grafana Patches AI Bug That Could Have Leaked User Data
ID: 77db2b08-37f7-5d5f-9653-a4b430bd71a7
STIX ID: report--77db2b08-37f7-5d5f-9653-a4b430bd71a7
Feed Name: Dark Reading
Noma security researchers disclosed "GrafanaGhost," a prompt-injection vulnerability in Grafana's AI assistant Markdown/image renderer that could allow an attacker to hide malicious instructions on externally served content (using protocol-relative URLs and an "INTENT" bypass) which the AI might process and send sensitive information to an attacker-controlled server; Grafana patched the issue after responsible disclosure, while the vendor and researchers dispute how much user interaction is required for exploitation and there is no evidence of in-the-wild abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
