github.com
https://github.com/grafana/grafana CVE-2025-41117
MEDIUM
XSS in Grafana Explore stack trace
Record summary
CVE-2025-41117 has a selected CVSS score of 6.8 (medium).
Description
Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 13, 2026 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
grafana/grafanaBrowse Grafana / grafana/grafanaDefault status: unaffected | CVE List | 12.2.0 to < 12.2.4+security-01 | affected |
| 12.3.0 to < 12.3.2+security-01 | affected | ||
grafana/grafana-enterpriseBrowse Grafana / grafana/grafana-enterpriseDefault status: unaffected | CVE List | 12.2.0 to < 12.2.4+security-01 | affected |
| 12.3.0 to < 12.3.2+security-01 | affected | ||
github.com/grafana/grafanaBrowse Go / github.com/grafana/grafana | GitHub Advisory | 12.2.0 to < 12.2.5 · Fixed in 12.2.5 | affected |
| 12.3.0 to < 12.3.3 · Fixed in 12.3.3 | affected |
References
7github.com
https://github.com/grafana/grafana/commit/4f624a5a01404da45d60063ae1ee2f184818cd42 github.com
https://github.com/grafana/grafana/commit/8dfa6446942873d76cd94c63a2d6b71a25e880da github.com
https://github.com/grafana/grafana/commit/ecff0d88680cea4ad32709cb3b94b790a7f58d25 grafana.com
https://grafana.com/security/security-advisories/CVE-2025-41117 grafana.comVendor advisory
https://grafana.com/security/security-advisories/cve-2025-41117 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-41117