More than 46,000 Grafana installations exposed online remain unpatched and vulnerable to a “client-side open redirect” security flaw, which allows the execution of malicious plugins and possible account takeover.
See also: Secure Boot flaw allows bootkit malware installation

The vulnerability is registered as CVE-2025-4123 and affects multiple versions of the open source platform, which is used to monitor and visualize infrastructure and application metrics.
The flaw was discovered by bug hunter Alvaro Balada and addressed in security updates released by Grafana Labs on May 21. However, according to researchers at application security firm OX Security, who are calling the flaw “The Grafana Ghost,” more than a third of installations accessible via the public internet remain vulnerable.
After identifying the versions vulnerable to the attack, the researchers assessed the extent of the exposure by correlating the data with the platform's distribution in the broader ecosystem.
They found that 128,864 Grafana installations are accessible over the internet, with 46,506 of them still running vulnerable versions that can be exploited by malicious actors. This corresponds to a rate of approximately 36%. OX Security’s in-depth analysis of the CVE-2025-4123 vulnerability revealed that, through a series of exploitation steps that combine client-side path traversal with open redirect mechanisms, attackers can trick victims into clicking on URLs that load a malicious Grafana plugin from a website controlled by the attacker.
See also: Cisco warns of ISE and CCP flaws
According to the researchers, the malicious links can be used to execute arbitrary JavaScript in the user's browser. Exploiting the flaw does not require elevated privileges and can work even when anonymous access.

The flaw allows attackers to hijack active user sessions, change account credentials, and, in cases where the Grafana Image Renderer, perform server-side request forgery (SSRF) to gain access to internal system resources.
Although Grafana's default Content Security Policy (CSP) offers some protection, it does not completely prevent exploitation due to limitations in its client-side implementation.
The exploit presented by OX Security shows that the CVE-2025-4123 vulnerability can be exploited from the user side and bypass modern browser canonicalization mechanisms through JavaScript routing that is native to Grafana.
This allows attackers to exploit inconsistencies in URL handling to serve malicious plugins that modify users' email addresses, making account takeovers via password reset extremely easy.
See also: Details of Cisco IOS XE flaw released publicly
Based on the above, it is clear that the CVE-2025-4123 flaw poses a serious threat to organizations using Grafana without having applied the latest security updates. The nature of the vulnerability — which relies on client-side mechanisms such as open redirect and path traversal— makes it particularly dangerous because it can be exploited without the need for elevated privileges and in scenarios where anonymous access is enabled. To mitigate the risk of exploitation, Grafana administrators are advised to upgrade to versions 10.4.18+security-01, 11.2.9+security-01, 11.3.6+security-01, 11.4.4+security-01, 11.5.4+security-01, 11.6.1+security-01 and 12.0.0+security-01.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
