MEDIUM6.3
GHSA-gxcp-jjxh-rwp4
Grafana: SQL Expressions Read File From Disk
Quick fix
GHSA-gxcp-jjxh-rwp4 — github.com/grafana/grafana: upgrade to the fixed version with the command below.
go get github.com/grafana/grafana@v1.9.2-0.20260513165311-fb7336fc36c1Details
A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/grafana/grafana
Introduced in:
0Fixed in: 1.9.2-0.20260513165311-fb7336fc36c1Fix
go get github.com/grafana/grafana@v1.9.2-0.20260513165311-fb7336fc36c1