A cross-site scripting (XSS) vulnerability exists in Grafana caused by client path traversal and open redirect. This allows attackers to redirect users to malicious websites that execute arbitrary JavaScript through custom frontend plugins. This vulnerability does not require editor permissions (as many other XSS usually does). If anonymous access is enabled, the XSS will work.This can be abused as a full read SSRF if the Grafana Image Renderer plugin is installed.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:7892 https://access.redhat.com/errata/RHSA-2025:7892
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7893 https://access.redhat.com/errata/RHSA-2025:7893
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:7894 https://access.redhat.com/errata/RHSA-2025:7894