Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/csv endpoint lacked validation of the filePath parameter that allowed an attacker to save a shared object to an arbitrary location that is then loaded by the Chromium process.
Instances are vulnerable if:
{
"cpes": [
"cpe:2.3:a:grafana:grafana-image-renderer:*:*:*:*:*:grafana:*:*"
],
"severity": "Critical"
}