Remote Code Execution Vulnerability in Grafana Image Renderer by Grafana
CVE-2025-11539
9.9CRITICAL
What is CVE-2025-11539?
The Grafana Image Renderer is susceptible to a remote code execution threat due to an arbitrary file write vulnerability. Specifically, the /render/csv endpoint fails to validate the filePath parameter properly. This oversight allows an attacker, particularly if they know the default authentication token or can access the image renderer endpoint, to write files to arbitrary locations. The danger lies in the fact that the saved file can then be executed by the Chromium process, potentially compromising the security of the system.
Affected Version(s)
grafana-image-renderer 1.0.0 <= 4.0.16