CVE-2025-4123 is a cross-site scripting (XSS) vulnerability in Grafana, stemming from a client path traversal and open redirect, which allows attackers to execute arbitrary JavaScript by redirecting users to a malicious frontend plugin. This medium-severity vulnerability (CVSS 6.1) has a low attack complexity and can lead to partial loss of confidentiality and integrity, with the potential for full read SSRF if the Grafana Image Renderer plugin is installed. While not yet in the KEV catalog, exploit code is publicly available via Nuclei templates and GitHub, and it has garnered significant community discussion and media coverage, indicating a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.4.18CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 11.2.0, < 11.2.9CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 11.3.0, < 11.3.6CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 11.4.0, < 11.4.4CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 11.5.0, < 11.5.4CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin
May 22, 2025XSS in Frontend Plugins in Grafana
May 21, 2025XSS in Frontend Plugins in Grafana
May 21, 2025XSS in Frontend Plugins in Grafana
May 21, 2025XSS in Frontend Plugins in Grafana
May 21, 2025XSS in Frontend Plugins in Grafana
May 21, 2025XSS in Frontend Plugins in Grafana
May 21, 2025grafana: Cross-site Scripting (XSS) in Grafana via Custom Frontend Plugins and Open Redirect
May 15, 2025