Impact
The vulnerability is a stored cross‑site scripting flaw in Grafana OSS’s Geomap panel. An Editor can insert a malicious script into the attribution field of an XYZ tile layer via a template variable. Once stored, the script executes automatically in the browsers of every viewer of the affected dashboard, enabling attackers to hijack user sessions, steal credentials, or perform other malicious actions.
Affected Systems
Grafana OSS dashboards that use the Geomap panel are potentially affected. The advisory does not specify exact release numbers, so any Grafana OSS deployment that includes a Geomap panel and has not yet applied a vendor‑issued fix could be vulnerable.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity, while the EPSS score of < 1% shows that exploitation is unlikely to be widespread, yet the flaw remains actionable because an attacker only needs Editor-level access to inject a payload. Once the malicious script is stored, it runs automatically for every subsequent dashboard viewer, creating a persistent risk across all users of the dashboard. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment