CVE-2025-4123
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
- EPSS probability
- 97.01%
- CWE
- CWE-79, CWE-601
- Published
- 2025-05-22
- Last modified
- 2026-04-29
Affected products
- Grafana Grafana
- Grafana Grafana
- Grafana Grafana
- Grafana Grafana
- Grafana Grafana
- Grafana Grafana
- Grafana Grafana
Weakness type
Related vulnerabilities
- CVE-2026-54694 — NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover
- CVE-2026-18147 — Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execution via crafted url
- CVE-2026-86772 — Snipe-IT 8.6.3 Stored XSS via Department Names
- CVE-2026-87814 — SiYuan before v3.8.2 Stored XSS via Asset Preview
- CVE-2026-87813 — SiYuan before v3.8.2 Stored XSS via unescaped asset filenames
- CVE-2026-87812 — SiYuan before v3.8.2 Stored XSS via Bazaar iconURL
- CVE-2026-87811 — SiYuan before v3.8.2 Stored XSS via notebook template paths
- CVE-2025-3271 — DOM-based XSS vulnerability in OpenText™ Documentum Webtop