CVE-2026-32117

Source
https://cve.org/CVERecord?id=CVE-2026-32117
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32117.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-32117
Aliases
  • GHSA-q6fh-6m3m-5948
Published
2026-03-11T21:28:38.122Z
Modified
2026-04-10T05:42:54.479893Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N CVSS Calculator
Summary
grafanacubism-panel : Stored XSS via javascript: URL in panel zoom link (Editor → Viewer)
Details

The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's zoom-link handler passes a dashboard-editor-supplied URL directly to window.location.assign() / window.open() with no scheme validation. An attacker with dashboard Editor privileges can set the link to a javascript: URI; when any Viewer drag-zooms on the panel, the payload executes in the Grafana origin.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32117.json"
}
References

Affected packages

Git / github.com/ekacnet/grafanacubism-panel

Affected ranges

Type
GIT
Repo
https://github.com/ekacnet/grafanacubism-panel
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.0.1
v0.0.2
v0.0.4
v0.0.5
v0.0.7
v0.0.8
v0.1.0
v0.1.1
v0.1.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32117.json"