JavaScript Injection Vulnerability in Grafana by Grafana Labs
CVE-2026-17033
What is CVE-2026-17033?
This vulnerability allows an authenticated attacker with Editor access to submit a malicious external Alertmanager alert that contains a controlled generatorURL. Although the attacker is permitted to create the alert, they cannot execute scripts in another user's Grafana session. However, due to a lack of URL-scheme sanitization in the way Grafana renders alert.generatorURL, attackers can exploit this feature. By inserting a bypass mechanism inside a JavaScript comment, they can execute arbitrary JavaScript code in the context of the Grafana origin if a user with read access clicks on a specially crafted 'See source' link. This poses a significant risk to users' sessions and data integrity.
Affected Version(s)
Grafana OSS 0 <= 12.3.11
Grafana OSS 12.4.0 <= 12.4.9
Grafana OSS 13.0.0 <= 13.0.7