PT-2025-21891 · Grafana+7 · Grafana+7

·

CVE-2025-4123

·

Published

2025-05-15

·

Updated

2026-06-07

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Grafana versions prior to 12.0.1
Description Grafana is susceptible to a cross-site scripting (XSS) vulnerability stemming from a combination of a client path traversal and an open redirect. This allows attackers to redirect users to a malicious website hosting a frontend plugin capable of executing arbitrary JavaScript. The vulnerability does not require editor permissions and is exploitable even with anonymous access enabled. If the Grafana Image Renderer plugin is installed, a full read SSRF can be achieved. The default Content-Security-Policy (CSP) in Grafana may offer some mitigation, but is not fully effective. Over 46,000 instances of Grafana were reported as unpatched and vulnerable. The vulnerability allows for potential account takeover and remote code execution.
Recommendations Update Grafana to version 12.0.1 or later.

Exploit

Fix

RCE

XSS

Open Redirect

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:7893
ALSA-2025:7894
ALSA-2025_7893
ALSA-2025_7894
ALT-PU-2025-10637
ALT-PU-2025-10789
BDU:2025-06002
BDU:2025-06809
BIT-GRAFANA-2025-4123
CESA-2025_7894
CVE-2025-4123
GHSA-Q53Q-GXQ9-MGRJ
GO-2025-3704
INFSA-2025_7893
INFSA-2025_7894
OPENSUSE-SU-2025:15171-1
OPENSUSE-SU-2025:15179-1
OPENSUSE-SU-2026:20654-1
RHSA-2025:7892
RHSA-2025:7893
RHSA-2025:7894
RHSA-2025:8665
RHSA-2025:8679
RHSA-2025:8680
RHSA-2025:8681
RHSA-2025:8683
RHSA-2025:8684
RHSA-2025:8685
RHSA-2025_7893
RHSA-2025_7894
SUSE-SU-2025:01985-1

Affected Products

Alt Linux
Almalinux
Centos
Grafana
Red Hat
Red Os
Rocky Linux
Suse