logo

Grafana releases critical security update for Image Renderer plugin

ID: 8232fdb5-46bf-559a-9dfd-d4e8f8eed8d8

STIX ID: report--8232fdb5-46bf-559a-9dfd-d4e8f8eed8d8

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-07-03

Date Updated: 2026-07-19

Author: Bill Toulas

...
...

Grafana Labs released a critical security update addressing four high-severity Chromium vulnerabilities (CVE-2025-5959, CVE-2025-6554, CVE-2025-6191, CVE-2025-6192) in the Image Renderer plugin and Synthetic Monitoring Agent that can lead to memory corruption and potential remote code execution via crafted HTML; users should upgrade the Image Renderer to 3.12.9+ and Synthetic Monitoring Agent to 0.38.3+ immediately (Grafana Cloud/Azure managed instances are already patched).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.