An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1).
Workaround
No workaround given by the vendor.
References
History
Thu, 15 Jan 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01 | |
| Weaknesses | CWE-601 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SICK AG
Published:
Updated: 2026-01-15T14:30:43.195Z
Reserved: 2026-01-08T09:59:08.086Z
Link: CVE-2026-0712
No data.
Status : Received
Published: 2026-01-15T13:16:04.490
Modified: 2026-01-15T13:16:04.490
Link: CVE-2026-0712
No data.
OpenCVE Enrichment
No data.
Weaknesses