PT-2025-30013 · Grafana+2 · Grafana Oss+2

·

CVE-2025-6197

·

Published

2025-06-11

·

Updated

2026-08-10

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions Grafana OSS versions 11.3.0 through 11.3.7 Grafana OSS versions 11.4.0 through 11.4.5 Grafana OSS versions 11.5.0 through 11.5.5 Grafana OSS versions 11.6.0 through 11.6.2 Grafana OSS versions 12.0.0 through 12.0.1
Description An open redirect issue exists in the OSS organization switching functionality. This flaw allows a remote attacker to redirect users to an arbitrary external website. For successful exploitation, the Grafana instance must contain multiple organizations, and the victim must belong to an organization different from the one specified in the URL. This open redirect can be chained with path traversal to facilitate cross-site scripting (XSS) attacks, where malicious scripts are injected into trusted websites.
Recommendations Update to version 11.3.8+security-01 Update to version 11.4.6+security-01 Update to version 11.5.6+security-01 Update to version 11.6.3+security-01 Update to version 12.0.2+security-01

Fix

XSS

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10637
ALT-PU-2025-10789
BDU:2025-08910
BDU:2025-09887
BIT-GRAFANA-2025-6023
BIT-GRAFANA-2025-6197
CVE-2025-6197
GHSA-VQPH-P5VC-G644
GO-2025-3817
OPENSUSE-SU-2025:15372-1
SUSE-SU-2025:3817-1
SUSE-SU-2025:3819-1
SUSE-SU-2025:4457-1
SUSE-SU-2025:4458-1
SUSE-SU-2025:4482-1

Affected Products

Alt Linux
Grafana Oss
Red Os