Grafana Security Update – 21 July 2025

Grafana has released security updates to address multiple vulnerabilities affecting Grafana.

The addressed vulnerabilities could allow the remote attacker to bypass security restrictions or perform Cross-Site Scripting attacks against the affected product.

Sample of the addressed vulnerabilities:

1. Grafana Cross-Site-Scripting (XSS) via scripted dashboards (CVE-2025-6023):

  • CVSS: 7.6
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Cross-Site Scripting
Vulnerabilities
  • CVE-2025-1088
  • CVE-2025-3415
  • CVE-2025-6197
  • CVE-2025-6023
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Grafana Security Update

References