PT-2024-7005 · Duckdb+3 · Duckdb+3

Published

2024-04-23

·

Updated

2026-03-11

·

CVE-2024-9264

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grafana versions prior to v11.0.6+security-01 Grafana versions prior to v11.1.7+security-01 Grafana versions prior to v11.2.2+security-01
Description The SQL Expressions experimental feature of Grafana allows for the evaluation of duckdb queries containing user input. These queries are insufficiently sanitized before being passed to duckdb, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack. The duckdb binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distributions. Over 538k results are found on ZoomEye, indicating a large number of potentially affected devices worldwide. The vulnerability is actively exploited in the wild.
Recommendations For versions prior to v11.0.6+security-01, update to v11.0.6+security-01 or later. For versions prior to v11.1.7+security-01, update to v11.1.7+security-01 or later. For versions prior to v11.2.2+security-01, update to v11.2.2+security-01 or later. As a temporary workaround, consider disabling the SQL Expressions feature until a patch is available. Restrict access to the duckdb binary to minimize the risk of exploitation. Avoid using the SQL Expressions feature with untrusted user input until the issue is resolved.

Exploit

Fix

RCE

Command Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024_1962
ALSA-2024_1963
ALSA-2024_2079
ALSA-2024_2562
ALSA-2024_2699
ALSA-2024_2724
ALSA-2024_7502
ALSA-2024_7550
ALSA-2024_8563
ALSA-2024_8846
ALSA-2024_8847
ALSA-2024_9051
ALSA-2025_16880
ALSA-2025_7118
ALSA-2025_7256
BDU:2024-08254
BIT-GRAFANA-2024-9264
CVE-2024-9264
GHSA-Q99M-QCV4-FPM7
GO-2024-3215
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14431-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3911-1
OPENSUSE-SU-2026:20654-1
SUSE-SU-2024:3911-1
SUSE-SU-2025:01985-1
SUSE-SU-2025:01987-1
SUSE-SU-2025:01989-1
SUSE-SU-2025:01991-1
SUSE-SU-2025_01987-1

Affected Products

Grafana
Red Os
Suse
Duckdb