JavaScript Injection Vulnerability in Grafana by Grafana Labs
CVE-2026-17033

6.8MEDIUM

Key Information:

Vendor

Grafana

Vendor
CVE Published:
24 August 2026

What is CVE-2026-17033?

This vulnerability allows an authenticated attacker with Editor access to submit a malicious external Alertmanager alert that contains a controlled generatorURL. Although the attacker is permitted to create the alert, they cannot execute scripts in another user's Grafana session. However, due to a lack of URL-scheme sanitization in the way Grafana renders alert.generatorURL, attackers can exploit this feature. By inserting a bypass mechanism inside a JavaScript comment, they can execute arbitrary JavaScript code in the context of the Grafana origin if a user with read access clicks on a specially crafted 'See source' link. This poses a significant risk to users' sessions and data integrity.

Affected Version(s)

Grafana OSS 0 <= 12.3.11

Grafana OSS 12.4.0 <= 12.4.9

Grafana OSS 13.0.0 <= 13.0.7

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nlgbao1340
.