CVE-2025-4123

EUVD-2025-16107
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF.

The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
grafanagrafana
𝑥
< 10.4.18
grafanagrafana
11.2.0 ≤
𝑥
< 11.2.9
grafanagrafana
11.3.0 ≤
𝑥
< 11.3.6
grafanagrafana
11.4.0 ≤
𝑥
< 11.4.4
grafanagrafana
11.5.0 ≤
𝑥
< 11.5.4
grafanagrafana
11.6.0 ≤
𝑥
< 11.6.1
grafanagrafana
10.4.18
grafanagrafana
11.2.9
grafanagrafana
11.3.6
grafanagrafana
11.4.4
grafanagrafana
11.5.4
grafanagrafana
11.6.1
grafanagrafana
12.0.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
grafana
focal
dne
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
resolute
dne
xenial
ignored
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
grafana
RHEL 8
0:9.2.10-23.el8_10
fixed
RHEL 8.2 AUS
0:6.3.6-7.el8_2
fixed
RHEL 9
0:10.2.6-13.el9_6
fixed
grafana-azure-monitor
RHEL 8.2 AUS
0:6.3.6-7.el8_2
fixed
grafana-cloudwatch
RHEL 8.2 AUS
0:6.3.6-7.el8_2
fixed
grafana-elasticsearch
RHEL 8.2 AUS
0:6.3.6-7.el8_2
fixed
grafana-graphite
RHEL 8.2 AUS
0:6.3.6-7.el8_2
fixed
grafana-influxdb
RHEL 8.2 AUS
0:6.3.6-7.el8_2
fixed
grafana-loki
RHEL 8.2 AUS
0:6.3.6-7.el8_2
fixed
grafana-mssql
RHEL 8.2 AUS
0:6.3.6-7.el8_2
fixed
grafana-mysql
RHEL 8.2 AUS
0:6.3.6-7.el8_2
fixed
grafana-opentsdb
RHEL 8.2 AUS
0:6.3.6-7.el8_2
fixed
grafana-postgres
RHEL 8.2 AUS
0:6.3.6-7.el8_2
fixed
grafana-prometheus
RHEL 8.2 AUS
0:6.3.6-7.el8_2
fixed
grafana-selinux
RHEL 8
0:9.2.10-23.el8_10
fixed
RHEL 9
0:10.2.6-13.el9_6
fixed
grafana-stackdriver
RHEL 8.2 AUS
0:6.3.6-7.el8_2
fixed