Over a Third of Grafana Instances Exposed to XSS Flaw
ID: 5dbd4e31-e86f-51ea-aa72-7885e07b34d8
STIX ID: report--5dbd4e31-e86f-51ea-aa72-7885e07b34d8
Feed Name: Infosecurity Magazine (News)
Security researchers warned of CVE-2025-4123 (the “Grafana Ghost”), a high-severity cross-site scripting vulnerability in Grafana that chains a client path traversal with an open redirect to load malicious frontend plugins; clicking a crafted link can enable arbitrary JavaScript execution, change account email/username to allow password resets and account takeover, and — if the Image Renderer plugin is installed — lead to full read SSRF. Ox Security estimates the flaw impacts roughly 36% of public Grafana instances (over 46,000) and also affects local instances; the issue was discovered and patched in May, and attackers can exploit it without editor permissions and even when anonymous access is enabled.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
