Sunday, 20 July

Sunday, 20 July2025

Critical Grafana Flaws Enable Malicious Redirects & Code Execution, Patch Immediately

Critical Grafana Flaws Enable Malicious Redirects & Code Execution, Patch Immediately
Two severe vulnerabilities, CVE20256023 and CVE20256197, have been discovered in Grafana versions 11.312.0. Attackers can exploit an XSS flaw via open redirects and path traversal to execute arbitrary JavaScriptwithout needing editor rightsleading to session hijacking and account takeover. A medium-grade open-redirect bug in organization switching could also escalate attacks. Grafana Labs has released security updates; users must upgrade or apply CSP policy and ingress fixes immediately.

Subscribe To Our Newsletter.

Full Name
Email