GHSA-q53q-gxq9-mgrj · Severity: high · Ecosystem: go — Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.
Conclusion & alert: CVE-2025-4123 is rated High Exploit Risk (79.1/100): CVSS High severity, with high exploitation likelihood (EPSS 6.89%, 91th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.63% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 52491 | exploit_db | edb | 2026-04-06 | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-27 | 5.26% | 6.89% | +1.63% |
| 2 | 2026-05-25 | 6.06% | 5.26% | -0.80% |
| 3 | 2026-05-23 | — | 6.06% | — |
Full EPSS history (76 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.6 | 3.1 | HIGH |
|
2.8 | 4.7 | [email protected] |
| 6.1 | 3.1 | MEDIUM |
|
2.8 | 2.7 | [email protected] |
GHSA-q53q-gxq9-mgrj · Severity: high · Ecosystem: go — Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2025-4123: 1 source package rows (grafana); 42 state rows across 2 repos (3.22-community, edge-community); fixed 0, open 42. | https://security.alpinelinux.org/vuln/CVE-2025-4123 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2025-4123 |
suse
|
high | CVE-2025-4123 severity important: SUSE including 11 source package names (gnutls-3.8.3-slfo.1.1_5.1, govulncheck-vulndb-0.0.20250527T204717-1.1, …), 42 product×package rows across 33 product lines (Image SL-Micro, Image SL-Micro-Base, … (33 product lines)): Fixed 40, Known Not Affected 2. | https://www.suse.com/security/cve/CVE-2025-4123/ |
ubuntu
|
medium | CVE-2025-4123 medium priority: Ubuntu including 1 source packages (grafana), 8 status rows across 8 suites (focal, jammy, noble, oracular, plucky, questing, upstream, xenial): DNE 6, needs-triage 2. | https://ubuntu.com/security/CVE-2025-4123 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| grafana | grafana | < 10.4.18 | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
| grafana | grafana | >= 11.2.0, < 11.2.9 | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
| grafana | grafana | >= 11.3.0, < 11.3.6 | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
| grafana | grafana | >= 11.4.0, < 11.4.4 | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
| grafana | grafana | >= 11.5.0, < 11.5.4 | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
| grafana | grafana | >= 11.6.0, < 11.6.1 | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
| grafana | grafana | 10.4.18 | cpe:2.3:a:grafana:grafana:10.4.18:-:*:*:*:*:*:* |
| grafana | grafana | 11.2.9 | cpe:2.3:a:grafana:grafana:11.2.9:-:*:*:*:*:*:* |
| grafana | grafana | 11.3.6 | cpe:2.3:a:grafana:grafana:11.3.6:-:*:*:*:*:*:* |
| grafana | grafana | 11.4.4 | cpe:2.3:a:grafana:grafana:11.4.4:-:*:*:*:*:*:* |
| grafana | grafana | 11.5.4 | cpe:2.3:a:grafana:grafana:11.5.4:-:*:*:*:*:*:* |
| grafana | grafana | 11.6.1 | cpe:2.3:a:grafana:grafana:11.6.1:-:*:*:*:*:*:* |
| grafana | grafana | 12.0.0 | cpe:2.3:a:grafana:grafana:12.0.0:-:*:*:*:*:*:* |