Grafana Security Update – 25 May 2025

Grafana has released security updates to address several vulnerabilities affecting Grafana OSS and Grafana Enterprise.

The addressed vulnerabilities could allow the remote attacker to gain elevated privileges, conduct cross-site scripting attacks, or delete the server administrator account.

Sample of the addressed vulnerabilities:

Grafana Cross-Site-Scripting (XSS) via Custom Loaded Frontend Plugin Vulnerability (CVE-2025-4123):

  • CVSS: 7.6
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Cross-Site Scripting
Vulnerabilities
  • CVE-2025-3580
  • CVE-2025-4123
  • CVE-2025-2703
  • CVE-2024-11741
  • CVE-2024-9476
  • CVE-2024-10452
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Grafana Security Update

References