← Vulnerability feed

Vulnerability record · CVE-2021-41174 · published 3 November 2021

CVE-2021-41174: Grafana AngularJS template injection XSS via crafted URL

Grafana · Grafana

Grafana renders AngularJS interpolation bindings ({{ }}) from a crafted URL without validation, allowing arbitrary JavaScript execution in the victim's browser. The flaw is reachable by an unauthenticated visitor who follows a malicious link to a page containing the login button. It matters because it enables script execution in the Grafana origin, which can be used to steal session data or act on behalf of the user.

6.1 CVSS 3.1 Medium EPSS 85% · top 0.3% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL referencing a vulnerable page, arbitrary JavaScript content may be executed within the context of the victim's browser. The user visiting the malicious link must be unauthenticated and the link must be for a page that contains the login button in the menu bar. The url has to be crafted to exploit AngularJS rendering and contain the interpolation binding for AngularJS expressions. AngularJS uses double curly braces for interpolation binding: {{ }} ex: {{constructor.constructor(‘alert(1)’)()}}. When the user follows the link and the page renders, the login button will contain the original link with a query parameter to force a redirect to the login page. The URL is not validated and the AngularJS rendering engine will execute the JavaScript expression contained in the URL. Users are advised to upgrade as soon as possible. If for some reason you cannot upgrade, you can use a reverse proxy or similar to block access to block the literal string {{ in the path.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS is medium (6.1) but EPSS is very high and the flaw allows script execution in a widely deployed monitoring platform, warranting prompt remediation.

What it is

Grafana renders AngularJS interpolation bindings ({{ }}) from a crafted URL without validation, allowing arbitrary JavaScript execution in the victim's browser. The flaw is reachable by an unauthenticated visitor who follows a malicious link to a page containing the login button. It matters because it enables script execution in the Grafana origin, which can be used to steal session data or act on behalf of the user.

Impact

An attacker can execute arbitrary JavaScript in the context of the victim's browser session on the Grafana instance. This can lead to theft of session tokens or other client-side data and actions performed as the victim.

Attack surface

Reached over the network by convincing a victim to visit a crafted URL; the victim must be unauthenticated and the target page must contain the login button in the menu bar. Exploitation requires user interaction (clicking the link) and no authentication.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.854 probability, 99.7th percentile), indicating elevated likelihood of exploitation activity. References include patch commits and vendor advisories, but no public exploit tag is present in the record.

What to do

  • Upgrade Grafana to a patched version as soon as possible.
  • If upgrade is not possible, block requests containing the literal string {{ in the path using a reverse proxy or WAF.
  • Restrict exposure of Grafana login pages to trusted networks where feasible.
  • Monitor vendor advisories and apply subsequent security updates promptly.

Detection

  • Search web/proxy logs for requests with {{ in the URL path or query string.
  • Alert on AngularJS expression patterns such as constructor.constructor or alert( in request URIs.
  • Review Grafana access logs for unusual redirects to the login page with encoded query parameters.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41174 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2021-43798Grafana plugin path directory traversal allows local file readGrafana versions 8.0.0-beta1 through 8.3.0 are vulnerable to directory traversal via the plugin URL path, allowing unauthenticated access to local fi…KEVEPSS 89%analysed7.3CVE-2021-39226Grafana snapshot endpoints allow unauthenticated view and deleteGrafana exposes snapshot endpoints that resolve to the snapshot with the lowest database key when accessed via literal paths such as /dashboard/snaps…KEVEPSS 100%analysed9.8CVE-2025-41115Grafana vulnerabilitySCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by i…EPSS 17%9.8CVE-2023-3128Grafana authentication bypass by spoofing vulnerabilityGrafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This…EPSS 4.0%9.8CVE-2022-28660Grafana missing authentication for critical function vulnerabilityThe querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Version…EPSS 1.1%9.8CVE-2022-26148Grafana Zabbix integration exposes cleartext password in page sourceGrafana through 7.3.4, when integrated with Zabbix, embeds the Zabbix account password and URL in the HTML source of api_jsonrpc.php. Anyone who can …EPSS 53%analysed9.8CVE-2020-27846Grafana vulnerabilityA signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from th…EPSS 4.9%9.8CVE-2018-15727Grafana authentication bypass via forged remember-me cookieGrafana versions 2.x, 3.x, 4.x before 4.6.4 and 5.x before 5.2.3 allow authentication bypass because an attacker can generate a valid "remember me" c…EPSS 64%analysed

Source: NIST National Vulnerability Database (record CVE-2021-41174), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.