6.8
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Description
Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field.
Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.
Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.
Basic Information
ID
CVE-2025-41117
Source
GRAFANA
Published
Feb 12, 2026 at 08:49
Affected Product
Vendor
Grafana
Product
grafana/grafana
Version
12.2.0
Affected Versions
Grafana grafana/grafana 12.2.0
Grafana grafana/grafana 12.3.0
Grafana grafana/grafana-enterprise 12.2.0
Grafana grafana/grafana-enterprise 12.3.0
Grafana grafana/grafana 12.3.0
Grafana grafana/grafana-enterprise 12.2.0
Grafana grafana/grafana-enterprise 12.3.0