Open Redirect Vulnerability in Grafana OSS Affecting Multiple Organizations
CVE-2025-6197

4.2MEDIUM

Key Information:

Vendor

Grafana

Status
Vendor
CVE Published:
18 July 2025

What is CVE-2025-6197?

An open redirect vulnerability has been detected in Grafana OSS, specifically within the organization switching functionality. This security issue arises when users switch organizations, allowing malicious actors to potentially redirect victims to arbitrary URLs. For exploitation, the Grafana instance must have multiple organizations, and the victim must belong to a different organization than the one indicated in the provided URL. Organizations using Grafana are advised to review their settings and implement necessary patches to mitigate this vulnerability.

Affected Version(s)

Grafana 12.0.x < 12.0.2+security-01

Grafana 11.6.x < 11.6.3+security-01

Grafana 11.5.x < 11.5.6+security-01

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dat Phung
.
CVE-2025-6197 : Open Redirect Vulnerability in Grafana OSS Affecting Multiple Organizations