CVE-2025-4123

High PUBLISHED

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers...

Grafana · Grafana

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
7.6 High

At a Glance

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

nuclei_scanner
CVE Published
May 22, 2025
Exploitation Reported
Jun 17, 2025
CVSS
7.6 High
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
Grafana
Grafana

10.4.18+security-01 to < 10.4.19

Affected
Grafana
Grafana

11.2.9+security-01 to < 11.2.10

Affected
Grafana
Grafana

11.3.6+security-01 to < 11.3.7

Affected
Grafana
Grafana

11.4.4+security-01 to < 11.4.5

Affected
Grafana
Grafana

11.5.4+security-01 to < 11.5.5

Affected
Grafana
Grafana

11.6.1+security-01 to < 11.6.2

Affected
Grafana
Grafana

12.0.0+security-01 to < 12.0.1

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.