<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Grafana OSS (12.3.0 to 12.4.10, 13.0.0 to 13.0.8, 13.1.0 to 13.1.5, 13.2.0 to 13.2.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/grafana-oss-12.3.0-to-12.4.10-13.0.0-to-13.0.8-13.1.0-to-13.1.5-13.2.0-to-13.2.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 19:53:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/grafana-oss-12.3.0-to-12.4.10-13.0.0-to-13.0.8-13.1.0-to-13.1.5-13.2.0-to-13.2.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Cross-Site Scripting Vulnerability in Grafana Geomap MapLibre</title><link>https://feed.craftedsignal.io/briefs/2026-09-grafana-xss/</link><pubDate>Fri, 18 Sep 2026 19:53:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-grafana-xss/</guid><description>Grafana OSS versions 12.x and 13.x contain a cross-site scripting (XSS) vulnerability (CVE-2026-76154) in the Geomap MapLibre component that could allow attackers to execute malicious scripts in a user's session.</description><content:encoded><![CDATA[<p>On September 17, 2026, the Cyber Centre reported multiple vulnerabilities affecting various versions of Grafana OSS. The most critical issue identified is CVE-2026-76154, a cross-site scripting (XSS) vulnerability located within the Geomap MapLibre component. This vulnerability poses a significant risk to organizations, as a successful exploit allows an unauthorized party to execute malicious JavaScript within the context of an authenticated user's session. Depending on the user's role and permissions, this could lead to sensitive data theft, session hijacking, or the performance of unauthorized administrative actions within the Grafana instance. Affected versions include 12.3.0 through 12.4.10, 13.0.0 through 13.0.8, 13.1.0 through 13.1.5, and 13.2.0 through 13.2.1. Given the potential impact on data integrity and user account security, administrators should prioritize updating to the latest secure version of Grafana.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-76154 enables attackers to bypass intended security controls by executing arbitrary client-side code. This can lead to full account takeover for authenticated users, unauthorized access to dashboard data, or the redirection of users to malicious infrastructure. The vulnerability impacts any organization relying on Grafana for operational monitoring and visualization, potentially exposing internal infrastructure data if the attacker gains administrative control.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching all affected Grafana OSS instances to the latest available version provided by Grafana. Review all active user sessions for suspicious activity and consider implementing stricter Content Security Policy (CSP) headers to mitigate potential XSS impacts. Monitor web access logs for unusual requests targeting the Geomap or MapLibre components as potential indicators of probing or exploitation attempts.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>xss</category><category>security-advisory</category></item></channel></rss>