Stored XSS in the Geomap panel tile-layer attribution

High
Advisory ID:
CVE-2026-9029
Published:
2026-06-09
Product:
Grafana
CVSS Score:
7.3
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Fixed Versions:
>=12.4.4
>=13.0.2

Summary

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting). Upgrade to a fixed version listed below.