CVE-2025-4123: XSS

Published May 7, 2025
·
Updated

A cross-site scripting (XSS) vulnerability exists in Grafana caused by client path traversal and open redirect. This allows attackers to redirect users to malicious websites that execute arbitrary JavaScript through custom frontend plugins. This vulnerability does not require editor permissions (as many other XSS usually does). If anonymous access is enabled, the XSS will work.This can be abused as a full read SSRF if the Grafana Image Renderer plugin is installed.

Other sources

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF.

The default Content-Security-Policy (CSP) in Grafana will block the XSS though the connect-src directive.

GitHub

Affected Software

15 affected componentsFixes available
Grafana Grafana
go/github.com/grafana/grafana<0.0.0-20250521183405-c7a690348df7
0.0.0-20250521183405-c7a690348df7
Grafana Grafana<10.4.18
Grafana Grafana>=11.2.0<11.2.9
Grafana Grafana>=11.3.0<11.3.6
Grafana Grafana>=11.4.0<11.4.4
Grafana Grafana>=11.5.0<11.5.4
Grafana Grafana>=11.6.0<11.6.1
Grafana Grafana=10.4.18
Grafana Grafana=11.2.9
Grafana Grafana=11.3.6
Grafana Grafana=11.4.4
Grafana Grafana=11.5.4
Grafana Grafana=11.6.1
Grafana Grafana=12.0.0

Event History

May 7, 2025
Data Sourced
via Red Hat·07:39 AM
DescriptionSeverityAffected Software
May 22, 2025
CVE Published
via MITRE·07:44 AM
Data Sourced
via MITRE·07:44 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
Affected Software
Advisory Published
via GitHub·09:33 AM
Data Sourced
via GitHub·09:33 AM
DescriptionSeverityWeaknessAffected Software
Jun 15, 2025
News Published
via BleepingComputer·02:07 PM
News Published
via BleepingComputer·02:08 PM
Apr 6, 2026
Exploit Published
via ExploitDB·12:00 AM
Known Exploited
04:29 PM

Frequently Asked Questions

1

What is the severity of CVE-2025-4123?

The severity of CVE-2025-4123 is classified as high due to its potential to allow redirection to malicious sites and execution of arbitrary JavaScript.

2

How do I fix CVE-2025-4123?

To fix CVE-2025-4123, update to the Grafana version 0.0.0-20250521183405-c7a690348df7 or later.

3

What products are affected by CVE-2025-4123?

CVE-2025-4123 affects both Grafana OSS and Enterprise editions.

4

What type of vulnerability is CVE-2025-4123?

CVE-2025-4123 is a cross-site scripting (XSS) vulnerability caused by client path traversal and open redirects.

5

Is user permission required to exploit CVE-2025-4123?

No, CVE-2025-4123 does not require editor permissions for exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203