logo

Over a Third of Grafana Instances Exposed to XSS Flaw

ID: 5dbd4e31-e86f-51ea-aa72-7885e07b34d8

STIX ID: report--5dbd4e31-e86f-51ea-aa72-7885e07b34d8

Feed Name: Infosecurity Magazine (News)

Threat Score
72/100

Date Published: 2025-06-16

Date Updated: 2026-04-22

...
...

Security researchers warned of CVE-2025-4123 (the “Grafana Ghost”), a high-severity cross-site scripting vulnerability in Grafana that chains a client path traversal with an open redirect to load malicious frontend plugins; clicking a crafted link can enable arbitrary JavaScript execution, change account email/username to allow password resets and account takeover, and — if the Image Renderer plugin is installed — lead to full read SSRF. Ox Security estimates the flaw impacts roughly 36% of public Grafana instances (over 46,000) and also affects local instances; the issue was discovered and patched in May, and attackers can exploit it without editor permissions and even when anonymous access is enabled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.