Grafana Labs has addressed four Chromium vulnerabilities in critical security updates for the Grafana Image Renderer plugin and Synthetic Monitoring Agent. Although the issues impact Chromium and were fixed by the open-source project two weeks ago, Grafana received a bug bounty submission from security researcher Alex Chapman proving their exploitability in the Grafana components. Grafana describes the update as a "critical severity security release" and advises users to apply the fixes for the vulnerabilities below as soon as possible: CVE-2025-5959 (high-severity, 8.8 score) – type confusion bug in the V8 JavaScript and WebAssembly engine allows remote code execution inside a sandbox via a crafted HTML pageCVE-2025-6554 (high-severity, 8.1 score) – type confusion in V8 enables attackers to perform arbitrary memory read/write through a malicious HTML pageCVE-2025-6191 (high-severity, 8.8 score) – integer overflow in V8 allows out-of-bounds memory access, potentially leading to code executionCVE-2025-6192 (high-severity, 8.8 score) – use-after-free vulnerability in Chrome's Metrics component could cause heap corruption exploitable via crafted HTML The security problems impact the Grafana Image Renderer versions prior to 3.12.9, and the Syntentic Monitoring Agent versions before 0.38.3. The Grafana Image Renderer is a widely deployed plugin in production environments where automated dashboard rendering for scheduled email reports and embedding in third-party systems is crucia...
Grafana releases critical security update for Image Renderer plugin
BleepingComputer
·Bill Toulas
·Published Jul 3, 2025
·Updated
Affected Software
2 affected components
Grafana Labs Grafana Image Renderer
Grafana Labs Synthetic Monitoring Agent
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical security update released by Grafana Labs for its Image Renderer plugin and Synthetic Monitoring Agent.
2
What security implications are discussed in the article?
The article highlights four Chromium vulnerabilities that were addressed in the security update.
3
What products or software are affected by the security update?
The affected products include the Grafana Image Renderer and the Synthetic Monitoring Agent.
4
Why is it important to update the Grafana Image Renderer plugin?
It is crucial to update the Grafana Image Renderer plugin to mitigate risks associated with the identified Chromium vulnerabilities.
5
Who released the security update discussed in the article?
The security update was released by Grafana Labs.