Remote Code Execution Vulnerability in Grafana Image Renderer by Grafana
CVE-2025-11539

9.9CRITICAL

Key Information:

Vendor

Grafana

Vendor
CVE Published:
9 October 2025

What is CVE-2025-11539?

The Grafana Image Renderer is susceptible to a remote code execution threat due to an arbitrary file write vulnerability. Specifically, the /render/csv endpoint fails to validate the filePath parameter properly. This oversight allows an attacker, particularly if they know the default authentication token or can access the image renderer endpoint, to write files to arbitrary locations. The danger lies in the fact that the saved file can then be executed by the Chromium process, potentially compromising the security of the system.

Affected Version(s)

grafana-image-renderer 1.0.0 <= 4.0.16

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-11539 : Remote Code Execution Vulnerability in Grafana Image Renderer by Grafana