
CVE-2026-32117 The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's zoom-link handler passes a dashboard-editor-supplied URL directly… https://www.cve.org/CVERecord?id=CVE-2026-32117
Post summary
The CVE‑record describes a flaw in Grafana’s grafanacubism‑panel plugin where the zoom‑link handler accepts arbitrary URLs supplied by the dashboard editor, but no PoC, exploit, active use, or mitigation is mentioned.
