VDB
Sign up
HIGH7.6

GHSA-q53q-gxq9-mgrj

Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin

Quick fix

GHSA-q53q-gxq9-mgrj — github.com/grafana/grafana: upgrade to the fixed version with the command below.

go get github.com/grafana/grafana@v0.0.0-20250521183405-c7a690348df7

Details

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF.

The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/grafana/grafana
Introduced in: 0Fixed in: 0.0.0-20250521183405-c7a690348df7
Fixgo get github.com/grafana/grafana@v0.0.0-20250521183405-c7a690348df7

References