VDB
Sign up
HIGH7.7

GHSA-f74p-cwhp-x2wx

Grafana Loki datasource plugin's callResource handler contains a path traversal vulnerability.

Quick fix

GHSA-f74p-cwhp-x2wx — github.com/grafana/grafana: upgrade to the fixed version with the command below.

go get github.com/grafana/grafana@v1.9.2-0.20260616075434-82ef13993059

Details

The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user can escape the plugin's resource sandbox and access administrative Loki endpoints (e.g. /config, /services, /ready) to extract sensitive backend configuration and internal service information.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/grafana/grafana
Introduced in: 2.0.0-beta1

No fixed version published yet for github.com/grafana/grafana (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/grafana/grafana
Introduced in: 12.0.0

No fixed version published yet for github.com/grafana/grafana (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/grafana/grafana
Introduced in: 12.3.0

No fixed version published yet for github.com/grafana/grafana (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/grafana/grafana
Introduced in: 13.0.0

No fixed version published yet for github.com/grafana/grafana (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/grafana/grafana
Introduced in: 12.4.0

No fixed version published yet for github.com/grafana/grafana (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/grafana/grafana
Introduced in: 0Fixed in: 1.9.2-0.20260616075434-82ef13993059
Fixgo get github.com/grafana/grafana@v1.9.2-0.20260616075434-82ef13993059

References