CVE-2025-6023

HIGH

Grafana OSS <12.0.2 - Open Redirect

Title source: llm
STIX 2.1

Description

An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01

Scores

CVSS v3 7.6
EPSS 0.3628
EPSS Percentile 98.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601 CWE-79
Status published
Products (6)
grafana/grafana 0 - 1.9.2-0.20250521205822-0ba0b99665a9Go
Grafana/Grafana 11.3.x - 11.3.8+security-01
Grafana/Grafana 11.4.x - 11.4.6+security-01
Grafana/Grafana 11.5.x - 11.5.6+security-01
Grafana/Grafana 11.6.x - 11.6.3+security-01
Grafana/Grafana 12.0.x - 12.0.2+security-01
Published Jul 18, 2025
Tracked Since Feb 18, 2026