
Vulnerability-spoiler-alert has detected its first two live “negative-days” in Grafana! CVE-2025-41117 (XSS) and CVE-2026-21722 (Privesc) are still unpublished right now, but is detectable via commits in the open-source repo. That’s at least 1 hour early. PoCs and more at https://vulnerabilityspoileralert.com
Post summary
The post announces the early detection of two unpublished Grafana vulnerabilities—an XSS and a privilege‑escalation flaw—providing a link to PoCs but no evidence of active exploitation or patches.


