CVE-2021-43798

HIGH KEV NUCLEI LAB

Grafana Plugin Path Traversal

Title source: metasploit

Description

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.

Exploits (58)

exploitdb WORKING POC
by s1gh · pythonwebappsmultiple
https://www.exploit-db.com/exploits/50581
nomisec WORKING POC 367 stars
by jas502n · infoleak
https://github.com/jas502n/Grafana-CVE-2021-43798
nomisec WORKING POC 268 stars
by A-D-Team · infoleak
https://github.com/A-D-Team/grafanaExp
nomisec WORKING POC 44 stars
by pedrohavay · poc
https://github.com/pedrohavay/exploit-grafana-CVE-2021-43798
nomisec WORKING POC 40 stars
by taythebot · infoleak
https://github.com/taythebot/CVE-2021-43798
nomisec WORKING POC 27 stars
by zer0yu · infoleak
https://github.com/zer0yu/CVE-2021-43798
nomisec WORKING POC 25 stars
by Mr-xn · infoleak
https://github.com/Mr-xn/CVE-2021-43798
nomisec WORKING POC 17 stars
by MoCh3n · poc
https://github.com/MoCh3n/CVE-2021-43798-grafana_fileread
nomisec WORKING POC 14 stars
by ScorpionsMAX · poc
https://github.com/ScorpionsMAX/CVE-2021-43798-Grafana-POC
nomisec WORKING POC 12 stars
by asaotomo · poc
https://github.com/asaotomo/CVE-2021-43798-Grafana-Exp
nomisec SCANNER 9 stars
by Mo0ns · poc
https://github.com/Mo0ns/Grafana_POC-CVE-2021-43798
nomisec WORKING POC 8 stars
by Sic4rio · infoleak
https://github.com/Sic4rio/Grafana-Decryptor-for-CVE-2021-43798
nomisec WORKING POC 6 stars
by kenuosec · poc
https://github.com/kenuosec/grafanaExp
nomisec WORKING POC 5 stars
by z3n70 · poc
https://github.com/z3n70/CVE-2021-43798
nomisec WORKING POC 4 stars
by s1gh · poc
https://github.com/s1gh/CVE-2021-43798
nomisec WORKING POC 3 stars
by K3ysTr0K3R · infoleak
https://github.com/K3ysTr0K3R/CVE-2021-43798-EXPLOIT
nomisec WORKING POC 3 stars
by hupe1980 · remote-auth
https://github.com/hupe1980/CVE-2021-43798
nomisec WORKING POC 2 stars
by wezoomagency · infoleak
https://github.com/wezoomagency/GrafXploit
nomisec WORKING POC 2 stars
by monke443 · infoleak
https://github.com/monke443/CVE-2021-43798
nomisec WORKING POC 2 stars
by 0xSAZZAD · local
https://github.com/0xSAZZAD/Grafana-CVE-2021-43798
nomisec WORKING POC 2 stars
by fanygit · poc
https://github.com/fanygit/Grafana-CVE-2021-43798Exp
nomisec WORKING POC 2 stars
by Ryze-T · poc
https://github.com/Ryze-T/CVE-2021-43798
nomisec WORKING POC 1 stars
by strikoder · infoleak
https://github.com/strikoder/Grafana-Password-Decryptor
nomisec WORKING POC 1 stars
by wagneralves · infoleak
https://github.com/wagneralves/CVE-2021-43798
nomisec WORKING POC 1 stars
by FAOG99 · infoleak
https://github.com/FAOG99/GrafanaDirectoryScanner
nomisec WORKING POC 1 stars
by Jroo1053 · infoleak
https://github.com/Jroo1053/GrafanaDirInclusion
nomisec WORKING POC 1 stars
by k3rwin · poc
https://github.com/k3rwin/CVE-2021-43798-Grafana
nomisec WORKING POC 1 stars
by LongWayHomie · poc
https://github.com/LongWayHomie/CVE-2021-43798
nomisec WORKING POC 1 stars
by lfz97 · poc
https://github.com/lfz97/CVE-2021-43798-Grafana-File-Read
nomisec WORKING POC
by kikechans · poc
https://github.com/kikechans/Grafana-LFI-Exploit-CVE-2021-43798-
nomisec WORKING POC
by Shoxake17 · infoleak
https://github.com/Shoxake17/CVE-2021-43798
gitlab WORKING POC
by bybsecs · infoleak
https://gitlab.com/bybsecs/Grafana_POC-CVE-2021-43798
gitlab WORKING POC
by bybsecs · infoleak
https://gitlab.com/bybsecs/CVE-2021-43798-Grafana-Exp
nomisec WORKING POC
by baktistr · poc
https://github.com/baktistr/cve-2021-43798-enum
nomisec WORKING POC
by 0xf3d0rq · poc
https://github.com/0xf3d0rq/CVE-2021-43798
github FAILED
by theeldruin · shellpoc
https://github.com/theeldruin/CVE-PoCs/tree/main/CVE-2021-43798-Grafana.sh
nomisec SCANNER
by abuyazeen · infoleak
https://github.com/abuyazeen/CVE-2021-43798-Grafana-path-traversal-tester
nomisec WORKING POC
by suljov · infoleak
https://github.com/suljov/Grafana-LFI-exploit
nomisec WORKING POC
by ravi5hanka · infoleak
https://github.com/ravi5hanka/CVE-2021-43798-Exploit-for-Windows-and-Linux
nomisec WORKING POC
by davidrxchester · poc
https://github.com/davidrxchester/Grafana-8.3-Directory-Traversal
nomisec WORKING POC
by hxlxmj · infoleak
https://github.com/hxlxmj/Grafxploit
nomisec WORKING POC
by MalekAlthubiany · infoleak
https://github.com/MalekAlthubiany/CVE-2021-43798
nomisec WORKING POC
by ticofookfook · infoleak
https://github.com/ticofookfook/CVE-2021-43798
nomisec WRITEUP
by Iris288 · infoleak
https://github.com/Iris288/CVE-2021-43798
nomisec WORKING POC
by katseyres2 · infoleak
https://github.com/katseyres2/CVE-2021-43798
nomisec WORKING POC
by victorhorowitz · remote
https://github.com/victorhorowitz/grafana-exploit-CVE-2021-43798
nomisec WORKING POC
by mauricelambert · remote
https://github.com/mauricelambert/LabAutomationCVE-2021-43798
nomisec WORKING POC
by G01d3nW01f · poc
https://github.com/G01d3nW01f/CVE-2021-43798
nomisec SCANNER
by halencarjunior · poc
https://github.com/halencarjunior/grafana-CVE-2021-43798
nomisec WORKING POC
by JiuBanSec · infoleak
https://github.com/JiuBanSec/Grafana-CVE-2021-43798
nomisec STUB
by gixxyboy · poc
https://github.com/gixxyboy/CVE-2021-43798
vulncheck_xdb WORKING POC
infoleak
https://github.com/f3d0rq/CVE-2021-43798-poc
vulncheck_xdb WORKING POC
infoleak
https://github.com/davidr-io/Grafana-8.3-Directory-Traversal
vulncheck_xdb WORKING POC
infoleak
https://github.com/aymenbouferroum/CVE-2021-43798_exploit
vulncheck_xdb WORKING POC
infoleak
https://github.com/k3rwin/CVE-2021-43798-Grafana-
vulncheck_xdb WORKING POC
infoleak
https://github.com/scopion/CVE-2021-43799
metasploit WORKING POC
by h00die, jordyv · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/grafana_plugin_traversal.rb

Nuclei Templates (1)

Grafana v8.x - Arbitrary File Read
HIGHVERIFIEDby z0ne,dhiyaneshDk,j4vaovo
Shodan: title:"Grafana" || cpe:"cpe:2.3:a:grafana:grafana" || http.title:"grafana"
FOFA: title="grafana" || app="grafana"

Scores

CVSS v3 7.5
EPSS 0.9444
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Lab Environment

COMMUNITY
Community Lab
docker pull vulhub/grafana:8.2.6
docker pull grafana/grafana-enterprise:8.2.0
+51 more repos

Details

CISA KEV 2025-10-09
VulnCheck KEV 2023-12-02
ENISA EUVD EUVD-2024-0581
CWE
CWE-22
Status published
Products (4)
grafana/grafana 8.0.0 beta1 (3 CPE variants)
grafana/grafana 8.3.0
grafana/grafana 8.0.1 - 8.0.7
grafana/grafana 8.3.0 - 8.3.1Go
Published Dec 07, 2021
KEV Added Oct 09, 2025
Tracked Since Feb 18, 2026