Help Center/ Cloud Container Engine/ Product Bulletin/ Vulnerability Notices/ Notice of Grafana Security Vulnerability (CVE-2025-4123)
Updated on 2025-07-25 GMT+08:00

Notice of Grafana Security Vulnerability (CVE-2025-4123)

Grafana is an open-source data visualization and monitoring tool. It is widely used by enterprises and organizations to collect, analyze, and display metrics and log data from different data sources.

Description

Table 1 Vulnerability details

Type

CVE-ID

Severity

Discovered

Code execution

CVE-2025-4123

High

2025-05-21

Impact

A vulnerability was found in the processing of the custom frontend plugin of Grafana. This vulnerability allows attackers to execute cross-site scripting (XSS) attacks by exploiting client path traversal and open redirection issues. Such attacks may result in arbitrary JavaScript execution and could redirect users to malicious websites. If anonymous access is enabled, an attack can be carried out without any privilege escalation.

Identification Method

  1. Go to Add-ons and check whether the Grafana add-on has been installed and, if it has been, what version.
    Figure 1 Viewing the installed add-on version

  2. If the add-on version is 1.3.2 or earlier, the vulnerability is present.

Solution

Do not expose Grafana to the Internet. CCE will release a new version of the Grafana add-on to fix this vulnerability. For details, see Grafana Release History.