Grafana · Loki Datasource Plugin · CVE-2026-42129
**Name of the Vulnerable Software and Affected Versions**
Loki datasource plugin (affected versions not specified)
**Description**
The `callResource` handler in the Loki datasource plugin contains a path traversal flaw. This allows an authenticated user with a Viewer role to escape the resource sandbox and access administrative endpoints such as '/config', '/services', and '/ready'. This access can be used to extract internal service information and sensitive backend configurations.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.