Stored XSS in the Geomap panel tile-layer attribution
High
- Advisory ID:
- CVE-2026-9029
- Published:
- 2026-06-09
- Product:
- Grafana
- CVSS Score:
- 7.3
- CVSS Vector:
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
- Fixed Versions:
- >=12.4.4>=13.0.2
Summary
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting). Upgrade to a fixed version listed below.