
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-6023 is an open redirect vulnerability in Grafana OSS that can be chained with path traversal to achieve cross-site scripting (XSS) attacks. The vulnerability was introduced in Grafana v11.5.0 and affects versions 11.3.x through 12.0.x. It was published on July 18, 2025, with patches released the same day. The CVSS v3.1 base score is 7.6 (High) (GitHub Advisory, Grafana Advisory).
The vulnerability is classified under CWE-601 (URL Redirection to Untrusted Site / Open Redirect) and CWE-79 (Cross-site Scripting). An unauthenticated attacker can craft a malicious URL that exploits Grafana's open redirect handling, which when combined with path traversal (CWE-22) techniques, allows injection of malicious scripts into the victim's browser context. Exploitation requires user interaction — specifically, a victim must click a crafted link. OPSWAT's Unit 515 research team later discovered that the initial fix was incomplete, potentially allowing full account takeover via a bypass of the patch (GitHub Advisory, OPSWAT Blog, ZeroPath Blog).
Successful exploitation can lead to theft of user credentials, session hijacking, and unauthorized actions performed on behalf of the victim within the Grafana interface. The high confidentiality impact reflects the risk of sensitive dashboard data, API keys, and session tokens being exfiltrated via injected scripts. Integrity and availability are also partially affected, as attackers could manipulate dashboard configurations or disrupt monitoring operations. The incomplete initial fix, as discovered by OPSWAT Unit 515, elevated the risk to full account takeover (OPSWAT Blog, GitHub Advisory).
As of the initial disclosure in July 2025, no public proof-of-concept exploit was confirmed; however, the EPSS score rose significantly to 7.087% (92nd percentile), indicating elevated exploitation probability (GitHub Advisory). GreyNoise subsequently reported coordinated exploitation attempts targeting Grafana instances in the wild (GreyNoise Blog). A Nuclei template for detection was added to the ProjectDiscovery repository, and the vulnerability appeared in multiple trending CVE lists. No specific threat actor attribution has been published. The vulnerability is not currently listed in the CISA KEV catalog based on available data.
../) to escape the intended redirect scope and point to an attacker-controlled resource.%2F..%2F, %2e%2e) in redirect parameters.redirectTo or similar parameters containing traversal patterns or external URLs; repeated requests from the same IP to redirect-handling endpoints.Grafana has released patched versions addressing CVE-2025-6023: 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01, and 11.3.8+security-01. Because OPSWAT Unit 515 identified an incomplete fix in the initial patches, organizations should ensure they are running the latest available release (12.1.0 or later where applicable). As additional mitigations, administrators should implement a strict Content Security Policy (CSP), enforce input validation and output encoding, and monitor for suspicious redirect activity. No configuration-only workaround has been published; upgrading is the recommended remediation (Grafana Advisory, OPSWAT Blog, Grafana Blog).
Grafana Labs published a security advisory and blog post on July 17–18, 2025, disclosing the vulnerability alongside CVE-2025-6197 (Grafana Blog). OPSWAT's Unit 515 team published notable follow-up research revealing that the initial patch was incomplete and could lead to full account takeover, drawing significant community attention (OPSWAT Blog). The vulnerability was covered by multiple security news outlets including GBHackers, SecurityOnline, and CyberSecurityNews, and discussed on Reddit's r/pwnhub and r/cybersecurity. The Canadian Centre for Cyber Security (CCCS) issued advisory AV25-439, and CISA included it in its weekly vulnerability bulletin (CISA Bulletin, CCCS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."