The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.4.0, a malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions. This is possible because the plugin allows arbitrary JavaScript code injection in the [Layout] → [Link] → [URL] field. Version 2.4.0 contains a fix for the issue.
History

Mon, 08 Sep 2025 23:00:00 +0000

Type Values Removed Values Added
Description The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.4.0, a malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions. This is possible because the plugin allows arbitrary JavaScript code injection in the [Layout] → [Link] → [URL] field. Version 2.4.0 contains a fix for the issue.
Title Volkov Labs Business Links plugin vulnerable to privilege escalation attack
Weaknesses CWE-79
CWE-83
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-09-08T22:44:04.967Z

Reserved: 2025-09-04T19:18:09.498Z

Link: CVE-2025-58746

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-08T23:15:35.973

Modified: 2025-09-08T23:15:35.973

Link: CVE-2025-58746

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.