CVE 6.8 MEDIUM

XSS in Grafana Explore stack trace_CVE-2025-41117

6.8 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Description

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field.

Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

Basic Information

ID CVE-2025-41117
Source GRAFANA
Published Feb 12, 2026 at 08:49

Affected Product

Vendor Grafana
Product grafana/grafana
Version 12.2.0
Affected Versions Grafana grafana/grafana 12.2.0
Grafana grafana/grafana 12.3.0
Grafana grafana/grafana-enterprise 12.2.0
Grafana grafana/grafana-enterprise 12.3.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.