CVE-2025-41117Disclosure(grafana / grafana)

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • grafana

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-12)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
grafana

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-11: 1Mentions · 2026-02-12: 2PoC Mentioned / Linked · 2026-02-11: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 202-1102-12
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-111
PoC1
2026-02-122
Disclosure2
Full discourse3 posts
  • spaceraccoon | Eugene Lim@spaceraccoonsec
    PoC

    Vulnerability-spoiler-alert has detected its first two live “negative-days” in Grafana! CVE-2025-41117 (XSS) and CVE-2026-21722 (Privesc) are still unpublished right now, but is detectable via commits in the open-source repo. That’s at least 1 hour early. PoCs and more at https://vulnerabilityspoileralert.com

    Post summary

    Vulnerability-spoiler-alert reports two unpublished Grafana CVEs—CVE-2025-41117 (XSS) and CVE-2026-21722 (Privesc)—and provides PoCs via a link.

    02602039211.6K
    25.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-41117 Cross-Site Scripting in Grafana Explore Traces via Jaeger HTTP API Datasource https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-41117

    Post summary

    The snippet announces CVE‑2025‑41117 as a Cross‑Site Scripting flaw in Grafana, but provides no PoC, exploit details, patch information, or evidence of exploitation.

    0001039
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-41117 Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScrip… https://www.cve.org/CVERecord?id=CVE-2025-41117

    Post summary

    The CVE report describes a potential XSS flaw where stack traces are rendered as raw HTML, allowing JavaScript injection, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    00000374
    56.5K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appgrafanagrafana---
Appgrafanagrafana12.2.4--
Appgrafanagrafana12.3.2--

Explore more