Impact
The vulnerability appears when Grafana extracts plugin archives without properly resolving symbolic links. A malicious archive can chain relative symbolic link entries so that files are written outside the intended plugin directory, allowing the attacker to drop an executable backend binary that runs with Grafana's process privileges. This leads to full remote code execution on the host. The weakness maps to path traversal (CWE-22), symbolic link attacks (CWE-59) and code injection through arbitrary file write (CWE-94).
Affected Systems
Affected systems include Grafana OSS and Grafana Enterprise deployments. No specific version range is listed, so all current installations that include the described extraction code are potentially vulnerable. Operators of any Grafana instance that permits plugin installation should assume the risk.
Risk and Exploitability
The CVSS score of 8.8 marks the flaw as high severity, and the EPSS score of less than 1% indicates that exploit attempts are currently rare, but the impact is catastrophic. The vulnerability is not yet listed in the CISA KEV catalog, yet any Grafana instance that accepts third‑party plugins—whether through the UI, grafana-cli, the GF_INSTALL_PLUGINS environment variable or pre‑install configuration—could be compromised. The attack vector is therefore limited to the plugin installation process, but once a plugin is installed the compromise is immediate and unrestricted.
OpenCVE Enrichment