Impact
A caller‑supplied X‑Grafana‑URL header together with the grafana_api_request tool allows an attacker to direct the Grafana MCP Server to make outbound HTTP requests to arbitrary IP addresses, methods, paths, and payloads. Because the destination is not validated against the configured Grafana instance, the flaw maps to CWE‑918 and results in server‑side request forgery. The attacker can reach internal, loopback, and link‑local network services, including sensitive metadata endpoints, and read the responses, potentially exposing confidential data or enabling further attacks.
Affected Systems
The vulnerability affects Grafana MCP Server and Grafana mcp‑grafana. No specific product versions are listed in the advisory; administrators should consult the vendor’s security advisories to determine whether their deployed versions are impacted.
Risk and Exploitability
The CVSS score of 9.1 classifies the flaw as high severity. No EPSS score is currently available, and the vulnerability is not listed in the CISA KEV catalog. The lack of destination validation means that an attacker who can invoke grafana_api_request—typically an authenticated or privileged user—can exploit the flaw easily to harvest data from internal services.
OpenCVE Enrichment