Grafana MCP server-side request forgery via X-Grafana-URL header
High
Advisory ID:CVE-2026-15583
Published:2026-07-15
Product:Grafana MCP
CVSS Score:8.6
CVSS Vector:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Fixed Versions:
>=0.17.1

Summary

A vulnerability has been discovered in the mcp-grafana project (https://github.com/grafana/mcp-grafana) where a confused-deputy flaw allows an unauthenticated remote attacker to exfiltrate the server’s environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This vulnerability is classified as Server-Side Request Forgery (SSRF) and also enables credentialed SSRF against arbitrary internal services, including cloud metadata endpoints. Upgrade to a fixed version listed below.