{"schema_version":"1.9.0","id":"CVE-2025-4123","published":"2025-05-22T07:44:09.491Z","modified":"2026-08-12T03:51:19.840997303Z","aliases":["BIT-grafana-2025-4123","GHSA-q53q-gxq9-mgrj","GO-2025-3704"],"related":["ALSA-2025:7893","ALSA-2025:7894","CGA-w8vp-454p-4x2m","SUSE-SU-2025:01985-1","openSUSE-SU-2025:15171-1","openSUSE-SU-2025:15179-1","openSUSE-SU-2026:20654-1"],"details":"A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF.\n\nThe default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/grafana/grafana","events":[{"introduced":"0"},{"fixed":"a33fc073bf8b395da943a32c08a1217f7a7a30e0"},{"introduced":"c57667e4481563f5e6cf945b03bc0626caa4dbeb"},{"fixed":"f8ae632c424a8537738ccbab7abb98cf3c9f9a4e"},{"introduced":"d9455ff7db73b694db7d412e49a68bec767f2b5a"},{"fixed":"dd23cb31de627ff9eb6f8cf1e882e7b6256442bf"},{"introduced":"b58701869e1a11b696010a6f28bd96b68a2cf0d0"},{"fixed":"284f22d41bd23c602a14526657f1a3cde2d42bf5"},{"introduced":"f7a938db9ad71c1558e93d8e29e69f42c8a5f50b"},{"fixed":"f974c99f30b1ef9d23792a771ae64f3c851de4a4"},{"introduced":"d2fdff9ee4d75c74bfd3a97c18a0b8e4d029f06e"},{"fixed":"ae23ead4d959aa73a5a0ffada60e4147d679523c"},{"introduced":"a33fc073bf8b395da943a32c08a1217f7a7a30e0"},{"last_affected":"4c0e7045f97f356716755b47183b22e7f12bb4bf"}],"database_specific":{"cpe":["cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*","cpe:2.3:a:grafana:grafana:10.4.18:-:*:*:*:*:*:*","cpe:2.3:a:grafana:grafana:11.2.9:-:*:*:*:*:*:*","cpe:2.3:a:grafana:grafana:11.3.6:-:*:*:*:*:*:*","cpe:2.3:a:grafana:grafana:11.4.4:-:*:*:*:*:*:*","cpe:2.3:a:grafana:grafana:11.5.4:-:*:*:*:*:*:*","cpe:2.3:a:grafana:grafana:11.6.1:-:*:*:*:*:*:*","cpe:2.3:a:grafana:grafana:12.0.0:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"10.4.18"},{"introduced":"11.2.0"},{"fixed":"11.2.9"},{"introduced":"11.3.0"},{"fixed":"11.3.6"},{"introduced":"11.4.0"},{"fixed":"11.4.4"},{"introduced":"11.5.0"},{"fixed":"11.5.4"},{"introduced":"11.6.0"},{"fixed":"11.6.1"},{"introduced":"10.4.18-NA"},{"last_affected":"10.4.18-NA"},{"introduced":"11.2.9-NA"},{"last_affected":"11.2.9-NA"},{"introduced":"11.3.6-NA"},{"last_affected":"11.3.6-NA"},{"introduced":"11.4.4-NA"},{"last_affected":"11.4.4-NA"},{"introduced":"11.5.4-NA"},{"last_affected":"11.5.4-NA"},{"introduced":"11.6.1-NA"},{"last_affected":"11.6.1-NA"},{"introduced":"12.0.0-NA"},{"last_affected":"12.0.0-NA"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["10.4.18-NA","11.2.9-NA","11.3.6-NA","11.4.4-NA","11.5.4-NA","11.6.1-NA","12.0.0-NA","v12.0.0","v11.3.2","v11.6.0","v11.2.8","pkg/promlib/v0.0.8","pkg/promlib/v0.0.7","v11.4.0","v11.2.5","v10.4.14","v10.4.13","v11.2.4","v11.3.1","v10.4.11","v11.2.3","v10.4.8","v10.4.6","v10.4.5","v10.4.4","pkg/promlib/v0.0.6","v10.4.3","pkg/promlib/v0.0.5","v10.4.2","pkg/promlib/v0.0.4","pkg/promlib/v0.0.3","v10.4.1","pkg/promlib/v0.0.2","pkg/promlib/v0.0.1","pkg/util/xorm/v0.0.1","v0.0.1-test","v10.0.0-preview","v0.0.0-cloud","v3.2.1-test","v8.5.16","v9.3.0-beta1","v8.4.0-beta1","v8.3.3","v6.5","v6.0.0-beta1","v5.,2.4","v5.0.0","v5.0.0-beta5","v5.0.0-beta4","v5.0.0-beta3","v5.0.0-beta2","v5.0.0-beta1","v4.6.0-beta1","v4.5.0","v4.5.0-beta1","v4.4.0","v3.1.0-beta1","v3.0.2","v3.0.1","v3.0.0-beta7","v3.0.0-beta6","v2.6.0","v2.6.0-beta1","v2.5.0","v2.0.2","v2.0.1","v2.0.0-beta3","v2.0.0-beta1","v1.9.1","v1.9.0","v1.9.0-rc1","v1.7.0-rc1","v1.6.1","v1.6.0","v1.5.4","v1.5.3","v1.5.2","v1.5.1","v1.5.0","v1.4.0","v1.3.0","v1.2.0","v1.1.0","v1.0.4","v1.0.3","v1.0.2","v1.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-4123.json"}}],"references":[{"type":"WEB","url":"https://www.exploit-db.com/exploits/52491"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/4xxx/CVE-2025-4123.json"},{"type":"ADVISORY","url":"https://grafana.com/blog/2025/05/23/grafana-security-release-medium-and-high-severity-security-fixes-for-cve-2025-4123-and-cve-2025-3580/"},{"type":"ADVISORY","url":"https://grafana.com/security/security-advisories/cve-2025-4123/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4123"}],"database_specific":{"cna_assigner":"GRAFANA","cwe_ids":["CWE-601","CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/4xxx/CVE-2025-4123.json","unresolved_ranges":[{"extracted_events":[{"introduced":"10.4.18+security-01"},{"fixed":"10.4.19"},{"introduced":"11.2.9+security-01"},{"fixed":"11.2.10"},{"introduced":"11.3.6+security-01"},{"fixed":"11.3.7"},{"introduced":"11.4.4+security-01"},{"fixed":"11.4.5"},{"introduced":"11.5.4+security-01"},{"fixed":"11.5.5"},{"introduced":"11.6.1+security-01"},{"fixed":"11.6.2"},{"introduced":"12.0.0+security-01"},{"fixed":"12.0.1"}],"source":"AFFECTED_FIELD"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L"}]}