Saturday, October 3, 2026

Grafana Flaws Allow User Redirection and Code Execution in Dashboards

Grafana Labs has released critical security patches addressing two significant vulnerabilities that could enable attackers to redirect users to malicious websites and execute arbitrary code within dashboard environments.

The security update addresses CVE-2025-6023, a high-severity cross-site scripting (XSS) vulnerability, and CVE-2025-6197, a medium-severity open redirect flaw, both discovered through the company’s bug bounty program.

Critical XSS Vulnerability Enables Code Execution

The more severe vulnerability, CVE-2025-6023, represents a cross-site scripting attack vector that exploits client path traversal and open redirect mechanisms within Grafana’s scripted dashboards functionality.

CVE IDSeverityCVSS ScoreAffected VersionsPrimary Impact
CVE-2025-6023High7.6>= Grafana 11.5.0XSS, Code Execution
CVE-2025-6197Medium4.2>= Grafana 11.5.0Open Redirect

This vulnerability carries a CVSS score of 7.6 and poses particular risks because it does not require editor permissions to execute.

When anonymous access is enabled, the XSS vulnerability becomes immediately exploitable, allowing attackers to redirect users to malicious websites that can execute arbitrary JavaScript code.

The vulnerability affects Grafana Cloud users due to the absence of a connect-src directive in the Content-Security-Policy, which is necessary to prevent attackers from fetching external JavaScript resources.

While attackers do not need direct access to the Grafana instance to craft malicious payloads, victims must be authenticated with at least Viewer permissions for the arbitrary JavaScript execution to succeed. Successful exploitation could result in session hijacking or complete account takeover.

CVE-2025-6197, the medium-severity vulnerability with a CVSS score of 4.2, stems from flaws in Grafana’s organization switching functionality.

This open redirect vulnerability requires specific conditions for exploitation: the Grafana instance must have multiple organizations, the targeted user must be a member of both organizations involved in the switch, and the attacker must know the organization ID currently being viewed.

Grafana Cloud users are not affected by this particular vulnerability since the cloud service does not support Organizations.

Grafana Labs has released security patches for versions 12.0.x, 11.6.x, 11.5.x, 11.4.x, and 11.3.x. The vulnerabilities were discovered by security researchers Hoa X. Nguyen from OPSWAT and Dat Phung through the company’s bug bounty program.

For organizations unable to immediately upgrade, Grafana recommends implementing Content Security Policy configurations or blocking specific URL patterns as temporary mitigation measures.

These vulnerabilities highlight the importance of maintaining updated Grafana installations and implementing robust security policies.

The rapid response from Grafana Labs, including coordinated disclosure with cloud providers and advance notification to customers, demonstrates effective vulnerability management practices.

Organizations should prioritize upgrading to the latest security-patched versions to prevent potential exploitation of these critical flaws.

Get Free Ultimate SOC Requirements Checklist Before you build, buy, or switch your SOC for 2025 - Download Now

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices

A newly identified IoT botnet, Cling, disguises its command-and-control...

Microsoft Warns ClickFix Attacks Use Fake CAPTCHA Lures to Execute Malicious Commands

Microsoft Threat Intelligence has identified a ClickFix campaign in...

Critical GitLab AI Gateway Flaw Lets Attackers Execute Arbitrary Commands

GitLab has issued emergency security updates for a critical...

AWS AI Agent Vulnerabilities Let Attackers Bypass Authentication and Steal Credentials

AWS has released security fixes for four vulnerabilities affecting...

Citrix NetScaler Appliances Reboot Repeatedly After 0-Day Security Update

Citrix NetScaler administrators report repeated appliance crashes and forced...

Sony PS5 Relapse Jailbreak Exploit Uses JSC Memory Corruption and Kernel UAF

A newly released PlayStation 5 jailbreak chain, called Relapse,...

Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root

Two critical vulnerabilities in the open-source Zammad helpdesk and...

Safari History Database Tags Can Reveal Users’ Browsing Themes in Forensic Investigations

Safari's History database contains a lesser-known tagging artifact that...

Related Articles

Recent News