Grafana MCP server-side request forgery via X-Grafana-URL header
High
- Advisory ID:
- CVE-2026-15583
- Published:
- 2026-07-15
- Product:
- Grafana MCP
- CVSS Score:
- 8.6
- CVSS Vector:
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Fixed Versions:
- >=0.17.1
Summary
A vulnerability has been discovered in the mcp-grafana project (https://github.com/grafana/mcp-grafana) where a confused-deputy flaw allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This vulnerability is classified as Server-Side Request Forgery (SSRF) and also enables credentialed SSRF against arbitrary internal services, including cloud metadata endpoints. Upgrade to a fixed version listed below.