The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.4.0, a malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions. This is possible because the plugin allows arbitrary JavaScript code injection in the [Layout] → [Link] → [URL] field. Version 2.4.0 contains a fix for the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 08 Sep 2025 23:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.4.0, a malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions. This is possible because the plugin allows arbitrary JavaScript code injection in the [Layout] → [Link] → [URL] field. Version 2.4.0 contains a fix for the issue. | |
Title | Volkov Labs Business Links plugin vulnerable to privilege escalation attack | |
Weaknesses | CWE-79 CWE-83 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-08T22:44:04.967Z
Reserved: 2025-09-04T19:18:09.498Z
Link: CVE-2025-58746

No data.

Status : Received
Published: 2025-09-08T23:15:35.973
Modified: 2025-09-08T23:15:35.973
Link: CVE-2025-58746

No data.

No data.