← Vulnerability feed

Vulnerability record · CVE-2025-4123 · published 22 May 2025

CVE-2025-4123: Grafana client path traversal and open redirect enable XSS and SSRF

Grafana · Grafana

Grafana contains a cross-site scripting flaw built from a client-side path traversal chained with an open redirect. Attackers can redirect a victim to a site hosting a malicious frontend plugin that runs arbitrary JavaScript, and if the Grafana Image Renderer plugin is present the open redirect can be turned into a full-read SSRF. The default Content-Security-Policy blocks the XSS via the connect-src directive, so exposure depends on CSP configuration.

6.1 CVSS 3.1 Medium EPSS 97% · top 0.1% CWE-79 · Cross-site scriptingCWE-601 · Open redirect
6.1CVSS 3.1 base score
97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityVery high EPSS and a public exploit exist, and the flaw can lead to XSS or SSRF, though the default CSP blocks the XSS path and CVSS is only 6.1.

What it is

Grafana contains a cross-site scripting flaw built from a client-side path traversal chained with an open redirect. Attackers can redirect a victim to a site hosting a malicious frontend plugin that runs arbitrary JavaScript, and if the Grafana Image Renderer plugin is present the open redirect can be turned into a full-read SSRF. The default Content-Security-Policy blocks the XSS via the connect-src directive, so exposure depends on CSP configuration.

Impact

An attacker can execute arbitrary JavaScript in a victim's Grafana session, and with the Image Renderer plugin installed can read internal resources via SSRF. No editor privileges are required, and anonymous access makes the XSS work without a logged-in user.

Attack surface

Reached over the network through a crafted URL that combines path traversal and an open redirect; the CVSS vector shows no privileges required but user interaction required (UI:R). If anonymous access is enabled, no authentication is needed for the XSS path.

Exploitation

Not listed in CISA KEV and no ransomware association, but EPSS is very high (0.97007, 99.888th percentile) and a public Exploit-DB entry (52491) exists, indicating active interest and available proof-of-concept code.

What to do

  • Upgrade Grafana to the fixed release referenced in the vendor advisory for CVE-2025-4123.
  • Keep the default Content-Security-Policy in place and verify the connect-src directive is not weakened, since it blocks the XSS.
  • Disable anonymous access unless it is strictly required.
  • Remove or restrict the Grafana Image Renderer plugin if it is not needed, to close the SSRF path.
  • Restrict outbound network access from Grafana to limit SSRF reach if the renderer must stay installed.

Detection

  • Monitor Grafana access logs for requests containing path traversal sequences combined with redirect parameters.
  • Alert on outbound connections from Grafana hosts to unexpected external or internal addresses, especially from the Image Renderer.
  • Review CSP headers served by Grafana to confirm connect-src has not been relaxed.
  • Hunt for requests to plugin or redirect endpoints with unusual external URLs in query parameters.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-4123 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2021-43798Grafana plugin path directory traversal allows local file readGrafana versions 8.0.0-beta1 through 8.3.0 are vulnerable to directory traversal via the plugin URL path, allowing unauthenticated access to local fi…KEVEPSS 89%analysed7.3CVE-2021-39226Grafana snapshot endpoints allow unauthenticated view and deleteGrafana exposes snapshot endpoints that resolve to the snapshot with the lowest database key when accessed via literal paths such as /dashboard/snaps…KEVEPSS 100%analysed9.8CVE-2025-41115Grafana vulnerabilitySCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by i…EPSS 17%9.8CVE-2023-3128Grafana authentication bypass by spoofing vulnerabilityGrafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This…EPSS 4.0%9.8CVE-2022-28660Grafana missing authentication for critical function vulnerabilityThe querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Version…EPSS 1.1%9.8CVE-2022-26148Grafana Zabbix integration exposes cleartext password in page sourceGrafana through 7.3.4, when integrated with Zabbix, embeds the Zabbix account password and URL in the HTML source of api_jsonrpc.php. Anyone who can …EPSS 53%analysed9.8CVE-2020-27846Grafana vulnerabilityA signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from th…EPSS 4.9%9.8CVE-2018-15727Grafana authentication bypass via forged remember-me cookieGrafana versions 2.x, 3.x, 4.x before 4.6.4 and 5.x before 5.2.3 allow authentication bypass because an attacker can generate a valid "remember me" c…EPSS 64%analysed

Source: NIST National Vulnerability Database (record CVE-2025-4123), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.