PT-2026-7657 · Grafana+1 · Grafana+1
Published
2026-02-11
·
Updated
2026-03-11
·
CVE-2025-41117
CVSS v2.0
7.1
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Grafana (affected versions not specified)
Description
The Explore Traces view in Grafana can render stack traces as raw HTML, potentially allowing malicious JavaScript injection into the browser. This requires malicious JavaScript to be entered into the stack trace field. Only datasources utilizing the Jaeger HTTP API are affected; Jaeger gRPC and Tempo datasources are not impacted.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grafana
Red Os