HomeSecurityZero-click Grafana AI attack allows data extraction

Zero-click Grafana AI attack allows data extraction

Indirect prompt injection is possible in AI-powered dashboards, allowing sensitive corporate data to be extracted without user authentication. Security researchers are warning of a critical issue in Grafana, dubbed GrafanaGhost , that allows attackers to leak sensitive data from Grafana environments, including financial metrics, infrastructure health data, private customer data, operational logs, and more.

Zero‑click Grafana AI attack

Noma Security disclosed the bug to the Grafana team, who reportedly released a fix.

Grafana is a widely used open source data visualization and observabilitythat allows organizations to monitor systems, applications, and business metrics in real time.

See also: Ninja Forms – File Upload: Vulnerability puts thousands of WordPress sites at risk

“GrafanaGhost shows how AI integration creates a huge security blind spot,” said Ram Varadarajan, CEO of Activio. “Because indirect prompt injection bypasses traditional defenses, without requiring credentials or user interaction, it allows attackers to silently extract sensitive operational telemetry data.”

GrafanaGhost: Grafana AI scam for data leakage

GrafanaGhost is essentially not a single bug but a chained exploit that combines multiple bypasses in application logic and AI guardrails.

The attack begins by identifying an injection point, a location where user-controlled input can be stored and later processed by Grafana’s AI components. Noma researchers found that crafted paths with indirect prompts could remain in the system and later be interpreted as legitimate inputs. From there, attackers use indirect prompt injection techniques to manipulate the AI ​​to execute malicious instructions.

The model is tricked into creating requests that include sensitive data while interpreting the instructions as harmless.

See also: Storm-1175: Zero-day exploit for Medusa ransomware deployment

Zero-click Grafana AI attack allows data extraction

In a disclosure, Noma said the key technical breakthrough came from bypassing client-side protections designed to prevent external image loading. By exploiting a flaw in URL validation, specifically using protocol-relative URLs, such as //attacker.com, the system incorrectly treats malicious external resources as safe, allowing outbound requests to the attacker's infrastructure.

Finally, the attack bypasses AI guardrails by inserting specific keywords, such as INTENT, into the commands to convince the model that the request was legitimate. Once processed, the system attempts to render an image, embedding sensitive data in the request sent to the attacker’s server. The chain essentially allows for automated, zero-click data extraction that is integrated into the normal dashboard workflow.

Varadrajan pointed this out, saying that attackers exploit the blind spot “by using the system components exactly as designed, but with instructions that the model cannot verify as malicious.”

See also: Flowise AI Platform: Critical vulnerability under active exploitation

Zero-click Grafana AI attack allows data extraction

Real danger or exaggeration?

Bradley Smith, SVP and deputy CISO at BeyondTrust, described the underlying technique as “well-documented,” noting that indirect prompt injection leading to data extraction is a known risk in AI-enabled platforms.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“This is not a universal bypass of Grafana,” he said. “It is a demonstration of what can happen when AI components process untrusted input without adequate architectural controls.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS