Remote Code Execution Vulnerability in Grafana Image Renderer by Grafana
CVE-2025-11539
What is CVE-2025-11539?
The Grafana Image Renderer is susceptible to a remote code execution threat due to an arbitrary file write vulnerability. Specifically, the /render/csv endpoint fails to validate the filePath parameter properly. This oversight allows an attacker, particularly if they know the default authentication token or can access the image renderer endpoint, to write files to arbitrary locations. The danger lies in the fact that the saved file can then be executed by the Chromium process, potentially compromising the security of the system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
grafana-image-renderer 1.0.0 <= 4.0.16
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved