GHSA-9g84-39mm-q4p3

Suggest an improvement
Source
https://github.com/advisories/GHSA-9g84-39mm-q4p3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9g84-39mm-q4p3/GHSA-9g84-39mm-q4p3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9g84-39mm-q4p3
Aliases
Downstream
CGA (20)
MINI (4)
Published
2026-06-22T15:30:46Z
Modified
2026-09-21T23:11:02Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Grafana geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug
Details

The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug. sanitizeTextPanelContent() runs on the raw template string before getTemplateSrv().replace() substitutes the variable value, which uses the glob format with no HTML escaping. The result is passed to OpenLayers via element.innerHTML. An Editor can set a textbox variable's default value to an XSS payload that executes for every user who opens the dashboard. This is a bypass of the CVE-2023-0507 fix

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-21T22:56:35Z",
    "nvd_published_at":  "2026-06-22T14:17:55Z",
    "severity":  "HIGH"
}
References

Affected packages

Go / github.com/grafana/grafana

Package

Name
github.com/grafana/grafana
View open source insights on deps.dev
Purl
pkg:golang/github.com/grafana/grafana

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0-beta1

Database specific

last_known_affected_version_range
"< 12.4.4"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9g84-39mm-q4p3/GHSA-9g84-39mm-q4p3.json"

Go / github.com/grafana/grafana

Package

Name
github.com/grafana/grafana
View open source insights on deps.dev
Purl
pkg:golang/github.com/grafana/grafana

Affected ranges

Type
SEMVER
Events
Introduced
13.0.0

Database specific

last_known_affected_version_range
"< 13.0.2"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9g84-39mm-q4p3/GHSA-9g84-39mm-q4p3.json"

Go / github.com/grafana/grafana

Package

Name
github.com/grafana/grafana
View open source insights on deps.dev
Purl
pkg:golang/github.com/grafana/grafana

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.9.2-0.20260616075434-82ef13993059

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9g84-39mm-q4p3/GHSA-9g84-39mm-q4p3.json"