Vulnerability GHSA-f74p-cwhp-x2wx
High Risk
HIGH RISK
CVSS Score: 7.7
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 22, 2026 at 03:30 PM UTC
Grafana Loki datasource plugin's callResource handler contains a path traversal vulnerability.
v0.0.0-cloud - v6.1.6+incompatible
v0.0.0-cloud - v6.1.6+incompatible
Summary
Grafana Loki datasource plugin's callResource handler contains a path traversal vulnerability.
Details
The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user can escape the plugin's resource sandbox and access administrative Loki endpoints (e.g. /config, /services, /ready) to extract sensitive backend configuration and internal service information.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
3 hours ago
Grafana: Pre-authentication denial of service in the public dashboard query handler in github.com/grafana/grafana
v0.0.1-test - v6.1.6+incompatible GO-2026-6541
v0.0.1-test - v6.1.6+incompatible GO-2026-6541
Unknown
3 hours ago
Grafana geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug in github.com/grafana/grafana
v0.0.1-test - v6.1.6+incompatible GO-2026-6542
v0.0.1-test - v6.1.6+incompatible GO-2026-6542
Unknown
3 hours ago
Grafana Loki datasource plugin's callResource handler contains a path traversal vulnerability. in github.com/grafana/grafana
v0.0.1-test - v6.1.6+incompatible GO-2026-6544
v0.0.1-test - v6.1.6+incompatible GO-2026-6544
Unknown
3 hours ago
Grafana: Path traversal in the Tempo and Loki data source plugins in github.com/grafana/grafana
v0.0.1-test - v6.1.6+incompatible GO-2026-6545
v0.0.1-test - v6.1.6+incompatible GO-2026-6545
Unknown
3 months ago
Grafana: Users can generate Service Account tokens after permissions removal in github.com/grafana/grafana
v0.0.1-test - v6.1.6+incompatible GO-2026-5708
v0.0.1-test - v6.1.6+incompatible GO-2026-5708
Impacted packages
Timeline
Published
3 months ago
June 22, 2026 at 03:30 PM UTC
Last Modified
2 hours ago
September 28, 2026 at 05:10 PM UTC