Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2025-4123Cross-site Scripting in Grafana

Severity
6.1MEDIUMNVD
CNA7.6VulnCheck7.6
EPSS
3.9%
top 11.76%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 22
Latest updateApr 6

Description

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

CVEListV5grafana/grafana10.4.18+security-0110.4.19+6
NVDgrafana/grafana11.2.011.2.9+12
Gogithub.com/grafana_grafana< 0.0.0-20250521183405-c7a690348df7

🔴Vulnerability Details

6
OSV
Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin in github.com/grafana/grafana2025-05-27
GHSA
Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin2025-05-22
OSV
CVE-2025-4123: A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect2025-05-22
CVEList
CVE-2025-4123: A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect2025-05-22
OSV
Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin2025-05-22

💥Exploits & PoCs

2
Exploit-DB
Grafana 11.6.0 - SSRF2026-04-06
Nuclei
Grafana - XSS / Open Redirect / SSRF via Client Path Traversal

🔍Detection Rules

2
Suricata
ET WEB_SPECIFIC_APPS Grafana Open Redirect (CVE-2025-4123) M22025-11-26
Suricata
ET WEB_SPECIFIC_APPS Grafana Account Takeover via Path Traversal & Open Redirect (CVE-2025-4123)2025-06-17

📋Vendor Advisories

2
Red Hat
grafana: Cross-site Scripting (XSS) in Grafana via Custom Frontend Plugins and Open Redirect2025-05-15
Microsoft
A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.2022-12-13

🕵️Threat Intelligence

1
Bleepingcomputer
Over 46,000 Grafana instances exposed to account takeover bug2025-06-15
CVE-2025-4123 — Cross-site Scripting in Grafana | cvebase