The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.4.0, a malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions. This is possible because the plugin allows arbitrary JavaScript code injection in the [Layout] → [Link] → [URL] field. Version 2.4.0 contains a fix for the issue.
History

Tue, 09 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 08 Sep 2025 23:00:00 +0000

Type Values Removed Values Added
Description The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.4.0, a malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions. This is possible because the plugin allows arbitrary JavaScript code injection in the [Layout] → [Link] → [URL] field. Version 2.4.0 contains a fix for the issue.
Title Volkov Labs Business Links plugin vulnerable to privilege escalation attack
Weaknesses CWE-79
CWE-83
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-09-08T22:44:04.967Z

Updated: 2025-09-09T13:29:42.747Z

Reserved: 2025-09-04T19:18:09.498Z

Link: CVE-2025-58746

cve-icon Vulnrichment

Updated: 2025-09-09T13:14:28.936Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-08T23:15:35.973

Modified: 2025-09-09T16:28:43.660

Link: CVE-2025-58746

cve-icon Redhat

No data.