Home

Description

The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript.

PUBLISHED Reserved 2025-03-24 | Published 2025-04-23 | Updated 2025-06-10 | Assigner GRAFANA




MEDIUM: 6.8CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L

Problem types

CWE-79

Product status

Default status
unaffected

11.6.0 (semver) before 11.6.0+security-01
affected

11.5.0 (semver) before 11.5.3+security-01
affected

11.4.0 (semver) before 11.4.3+security-01
affected

11.3.0 (semver) before 11.3.5+security-01
affected

11.2.0 (semver) before 11.2.8+security-01
affected

Default status
unaffected

11.6.0 (semver) before 11.6.0+security-01
affected

11.5.0 (semver) before 11.5.3+security-01
affected

11.4.0 (semver) before 11.4.3+security-01
affected

11.3.0 (semver) before 11.3.5+security-01
affected

11.2.0 (semver) before 11.2.8+security-01
affected

Credits

Paul Gerste (Sonar) finder

References

grafana.com/security/security-advisories/cve-2025-2703

www.sonarsource.com/...tecting-xss-in-grafana-cve-2025-2703/

cve.org (CVE-2025-2703)

nvd.nist.gov (CVE-2025-2703)