CVE-2025-11539
Grafana vulnerability analysis and mitigation

Overview

Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability in versions 1.0.0 through 4.0.16. The vulnerability was discovered and disclosed on October 9, 2025, and is tracked as CVE-2025-11539. The issue affects the /render/csv endpoint which lacks proper validation of the filePath parameter, allowing attackers to save a shared object to arbitrary locations that can then be loaded by the Chromium process (Grafana Advisory).

Technical details

The vulnerability exists in the /render/csv endpoint where insufficient validation of the filePath parameter enables arbitrary file write capabilities. The vulnerability is rated as Critical with a CVSS v3.1 score of 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Two conditions must be met for successful exploitation: 1) The default authentication token (authToken) must either remain unchanged or be known to the attacker, and 2) The attacker must have network access to the image renderer endpoint (Grafana Advisory).

Impact

If successfully exploited, this vulnerability allows attackers to execute arbitrary code through the Chromium process by leveraging the arbitrary file write capability. The high CVSS score of 9.9 indicates severe potential impact on the confidentiality, integrity, and availability of the affected systems (Grafana Advisory).

Mitigation and workarounds

Users should immediately upgrade to Grafana Image Renderer version 4.0.17 or later, which contains the fix for this vulnerability. The patch was released on October 9, 2025 (GitHub Release).

Additional resources


SourceThis report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11539CRITICAL9.9
  • GrafanaGrafana
  • cpe:2.3:a:grafana:grafana
NoYesOct 09, 2025
CVE-2025-58754HIGH7.5
  • JavaScriptJavaScript
  • axios
NoYesSep 12, 2025
CVE-2025-47906MEDIUM6.5
  • cAdvisorcAdvisor
  • container-tools:rhel8::runc
NoYesSep 18, 2025
CVE-2025-47910MEDIUM5.4
  • Terraform CommunityTerraform Community
  • cri-o1.34-debugsource
NoYesSep 22, 2025
CVE-2025-9308MEDIUM4.8
  • GrafanaGrafana
  • grafana-mssql
NoYesAug 21, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management