Vulnerability record · CVE-2025-4123 · published 22 May 2025
CVE-2025-4123: Grafana client path traversal and open redirect enable XSS and SSRF
Grafana · Grafana
Grafana contains a cross-site scripting flaw built from a client-side path traversal chained with an open redirect. Attackers can redirect a victim to a site hosting a malicious frontend plugin that runs arbitrary JavaScript, and if the Grafana Image Renderer plugin is present the open redirect can be turned into a full-read SSRF. The default Content-Security-Policy blocks the XSS via the connect-src directive, so exposure depends on CSP configuration.
Description
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityVery high EPSS and a public exploit exist, and the flaw can lead to XSS or SSRF, though the default CSP blocks the XSS path and CVSS is only 6.1.
What it is
Grafana contains a cross-site scripting flaw built from a client-side path traversal chained with an open redirect. Attackers can redirect a victim to a site hosting a malicious frontend plugin that runs arbitrary JavaScript, and if the Grafana Image Renderer plugin is present the open redirect can be turned into a full-read SSRF. The default Content-Security-Policy blocks the XSS via the connect-src directive, so exposure depends on CSP configuration.
Impact
An attacker can execute arbitrary JavaScript in a victim's Grafana session, and with the Image Renderer plugin installed can read internal resources via SSRF. No editor privileges are required, and anonymous access makes the XSS work without a logged-in user.
Attack surface
Reached over the network through a crafted URL that combines path traversal and an open redirect; the CVSS vector shows no privileges required but user interaction required (UI:R). If anonymous access is enabled, no authentication is needed for the XSS path.
Exploitation
Not listed in CISA KEV and no ransomware association, but EPSS is very high (0.97007, 99.888th percentile) and a public Exploit-DB entry (52491) exists, indicating active interest and available proof-of-concept code.
What to do
- Upgrade Grafana to the fixed release referenced in the vendor advisory for CVE-2025-4123.
- Keep the default Content-Security-Policy in place and verify the connect-src directive is not weakened, since it blocks the XSS.
- Disable anonymous access unless it is strictly required.
- Remove or restrict the Grafana Image Renderer plugin if it is not needed, to close the SSRF path.
- Restrict outbound network access from Grafana to limit SSRF reach if the renderer must stay installed.
Detection
- Monitor Grafana access logs for requests containing path traversal sequences combined with redirect parameters.
- Alert on outbound connections from Grafana hosts to unexpected external or internal addresses, especially from the Image Renderer.
- Review CSP headers served by Grafana to confirm connect-src has not been relaxed.
- Hunt for requests to plugin or redirect endpoints with unusual external URLs in query parameters.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-4123 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-4123), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.