Indirect prompt injection is possible in AI-powered dashboards, allowing sensitive corporate data to be extracted without user authentication. Security researchers are warning of a critical issue in Grafana, dubbed GrafanaGhost , that allows attackers to leak sensitive data from Grafana environments, including financial metrics, infrastructure health data, private customer data, operational logs, and more.

Noma Security disclosed the bug to the Grafana team, who reportedly released a fix.
Grafana is a widely used open source data visualization and observabilitythat allows organizations to monitor systems, applications, and business metrics in real time.
See also: Ninja Forms – File Upload: Vulnerability puts thousands of WordPress sites at risk
“GrafanaGhost shows how AI integration creates a huge security blind spot,” said Ram Varadarajan, CEO of Activio. “Because indirect prompt injection bypasses traditional defenses, without requiring credentials or user interaction, it allows attackers to silently extract sensitive operational telemetry data.”
GrafanaGhost: Grafana AI scam for data leakage
GrafanaGhost is essentially not a single bug but a chained exploit that combines multiple bypasses in application logic and AI guardrails.
The attack begins by identifying an injection point, a location where user-controlled input can be stored and later processed by Grafana’s AI components. Noma researchers found that crafted paths with indirect prompts could remain in the system and later be interpreted as legitimate inputs. From there, attackers use indirect prompt injection techniques to manipulate the AI to execute malicious instructions.
The model is tricked into creating requests that include sensitive data while interpreting the instructions as harmless.
See also: Storm-1175: Zero-day exploit for Medusa ransomware deployment

In a disclosure, Noma said the key technical breakthrough came from bypassing client-side protections designed to prevent external image loading. By exploiting a flaw in URL validation, specifically using protocol-relative URLs, such as //attacker.com, the system incorrectly treats malicious external resources as safe, allowing outbound requests to the attacker's infrastructure.
Finally, the attack bypasses AI guardrails by inserting specific keywords, such as INTENT, into the commands to convince the model that the request was legitimate. Once processed, the system attempts to render an image, embedding sensitive data in the request sent to the attacker’s server. The chain essentially allows for automated, zero-click data extraction that is integrated into the normal dashboard workflow.
Varadrajan pointed this out, saying that attackers exploit the blind spot “by using the system components exactly as designed, but with instructions that the model cannot verify as malicious.”
See also: Flowise AI Platform: Critical vulnerability under active exploitation

Real danger or exaggeration?
Bradley Smith, SVP and deputy CISO at BeyondTrust, described the underlying technique as “well-documented,” noting that indirect prompt injection leading to data extraction is a known risk in AI-enabled platforms.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
“This is not a universal bypass of Grafana,” he said. “It is a demonstration of what can happen when AI components process untrusted input without adequate architectural controls.”
