CVE-2025-4123PoC(grafana / grafana)

MEDIUMCVSS 6.1 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for grafana grafana systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-601

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • grafana

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-03-26); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
grafana

7 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-26: 1Mentions · 2026-04-07: 1Mentions · 2026-05-25: 1Mentions · 2026-06-07: 1PoC Mentioned / Linked · 2026-03-26: 1Active Exploitation · 2026-04-07: 1Technical Details · 2026-03-26: 1Technical Details · 2026-04-07: 1Technical Details · 2026-06-07: 103-2604-0705-2506-07
Signal classification4 categories
PoC
125.0%
Active Exploitation
125.0%
General
125.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-261
PoC1
2026-04-071
Active Exploitation1
2026-05-251
General1
2026-06-071
Disclosure1
Full discourse4 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-4123 - high 🚨 Grafana - XSS / Open Redirect / SSRF via Client Path Traversal > An open redirect vulnerability in Grafana can be chained with other issues, such as X... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-4123 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet discloses a new high‑severity Grafana vulnerability (CVE‑2025‑4123) characterized by XSS, open redirect, and SSRF via client path traversal, linking to a Project Discovery library entry but offering no exploitation code or patch details.

    00020129
    952 followersView on X
  • Mohamed_Nowisar1878@nowisar1878
    General

    @Zierax_x Hi bro, hope you're doing great. I'm trying the scanner on a website vulnerable to CVE-2025-4123 and it's not working

    Post summary

    The text merely notes a vulnerability (CVE-2025-4123) and a scanner failure, with no further technical or exploit information provided.

    10010209
    35 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis reveals attackers exploiting CVE-2025-4123 to manipulate Grafana's AI components through prompt injection, bypassing guardrails to exfiltrate sensitive data via covert image tags. The attack chain demonstrates how compromised AI models enable lateral movement across monitoring environments. Runtime segmentation could help contain such AI-driven breach chains. #CloudSecurity #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/grafana-2026-prompt-injection-data-exfiltration

    Post summary

    A threat report indicates that CVE‑2025‑4123 is being actively exploited in Grafana, leveraging prompt injection to bypass AI guardrails and exfiltrate data through image tags, highlighting the need for runtime segmentation to contain the breach.

    00000209
    1.9K followersView on X
  • ‘BBWriteups’@bbwriteup
    PoC

    "CVE-2025–4123 Grafana Open Redirect & SSRF — Full PoC — CVSS 7.6 HIGH" by Dharanis #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/@dhxrxx/cve-2025-4123-grafana-open-redirect-ssrf-full-poc-cvss-7-6-high-8a61c7fd675c

    Post summary

    The text announces a full PoC for CVE‑2025‑4123, detailing its Open Redirect & SSRF nature and a CVSS rating, without discussing exploitation, patches, or false positives.

    00000195
    554 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appgrafanagrafana---
Appgrafanagrafana10.4.18--
Appgrafanagrafana11.2.9--
Appgrafanagrafana11.3.6--
Appgrafanagrafana11.4.4--
Appgrafanagrafana11.5.4--
Appgrafanagrafana11.6.1--
Appgrafanagrafana12.0.0--

Explore more