GrafanaGhost Vulnerability Allows Data Theft via AI Injection
ID: e0ff0ca4-5463-552a-b83e-6c3e28251d49
STIX ID: report--e0ff0ca4-5463-552a-b83e-6c3e28251d49
Feed Name: HackRead
Threat Score
Noma Security disclosed "GrafanaGhost", a vulnerability in Grafana that leverages indirect prompt injection and protocol-relative URLs to trick AI components into sending sensitive data to an attacker-controlled server without user interaction; the report details the attack chain, technical vector, and mixed expert opinions on practical exploitability against hardened deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
