Grafana OSS Open Redirect Vulnerability in Organization Switching Functionality

Vulnerability

A medium severity open redirect vulnerability has been identified in Grafana OSS versions 11.5.0 and later, excluding Grafana Cloud. This vulnerability arises from the organization switching feature, allowing attackers to redirect users to malicious websites. Exploitation requires knowledge of the victim's current organization and the existence of multiple organizations within the Grafana instance.

Impact

Successful exploitation allows for open redirection, which could be used to achieve cross-site scripting (XSS) by redirecting users to a site that executes malicious JavaScript, similar to CVE-2025-6023.

Remediation

Users can upgrade to Grafana versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 or 11.3.8+security-01. If upgrading is not possible, Grafana URLs starting with '/'' or '%2F' can be blocked in ingress, or the instance can be configured to have only one organization available.

Added: Jul 18, 2025, 8:33 AM
Updated: Jul 18, 2025, 8:33 AM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
1.0
exploitability
6.0
remediation
7.9
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.