Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-6023

45
FAUCET Score

CVE-2025-6023 describes an open redirect vulnerability in Grafana OSS, introduced in version 11.5.0, which can be chained with path traversal to enable Cross-Site Scripting (XSS) attacks. This vulnerability carries a high CVSS score of 7.6, indicating a significant risk due to its network-based attack vector and low attack complexity, potentially leading to high confidentiality impact and low integrity/availability impact. While no public exploits or active exploitation have been observed, and community discussion is minimal, organizations using affected Grafana versions should upgrade to patched versions (12.0.2+, 11.6.3+, 11.5.6+, 11.4.6+, or 11.3.8+) to mitigate the risk.

Impacted Technologies

VendorProductVersion(s)CPE
GrafanaGrafana
>= 11.3.x, < 11.3.8+security-01, >= 11.4.x, < 11.4.6+security-01, >= 11.5.x, < 11.5.6+security-01, >= 11.6.x, < 11.6.3+security-01, >= 12.0.x, < 12.0.2+security-01CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

7.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
37.56%
Probability of exploitation in next 30 days
EPSS Percentile
98.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.3756 is in the 99th percentile among its peer group of 14,855 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 1.9.2-0.20250521205822-0ba0b99665a9
nodejspatch availablevia llm_extracted
View patch
apollographqlvendor investigatingvia llm_extracted
View patch
chainsafevendor investigatingvia llm_extracted
View patch
jenkinsvendor investigatingvia llm_extracted
View patch
kenticovendor investigatingvia llm_extracted
View patch
zimbravendor investigatingvia llm_extracted
View patch

Vendor Advisories (8)

redhatCVE-2025-6023Important

grafana: Cross Site Scripting in Grafana

Jul 22, 2025
goGHSA-vqph-p5vc-g644high

Grafana is vulnerable to XSS attacks through open redirects and path traversal

Jul 18, 2025
kenticollm-kentico-e4c350ca7f6e18d8HIGH

XSS in Scripted Dashboards in Grafana

Jul 18, 2025
chainsafellm-chainsafe-8297f5882d55199bHIGH

XSS in Scripted Dashboards in Grafana

Jul 18, 2025
apollographqlllm-apollographql-7ed2788a13434214HIGH

XSS in Scripted Dashboards in Grafana

Jul 18, 2025
jenkinsllm-jenkins-9f914f01c6f966f1HIGH

XSS in Scripted Dashboards in Grafana

Jul 18, 2025
nodejsllm-nodejs-a326563e379ff5b3HIGH

XSS in Scripted Dashboards in Grafana

Jul 18, 2025
zimbrallm-zimbra-f5f1142dc6a95cf8HIGH

XSS in Scripted Dashboards in Grafana

Jul 18, 2025

References

grafana.com / blog/2025/07/17/grafana-security-release-medium-and-high-severity-fixes-for-cve-2025-6197-and-cve-2025-6023
grafana.com / security/security-advisories/cve-2025-6023