GPU VulnDB

Database/Control plane, storage & DevOps

Grafana Alerting: Editor can exfiltrate contact point credentials by retargeting the test endpoint

CVSS 1.3CVE-2025-12141Control plane, storage & DevOpscurated

Impact

A user holding alert.notifications:write or alert.notifications.receivers:test - granted by the Contact Point Writer role, which the basic Editor role includes - can edit a contact point created by someone else, point its endpoint URL at a server they control, and invoke the test function. The redacted secure settings are sent to that server, handing over the stored credentials: Slack tokens, webhook secrets, PagerDuty keys. In a GPU cluster this is the alerting path for node health, thermal and fabric events, so the stolen credentials give access to the operator's notification channels and whatever those integrations can reach. Grafana scores it 1.3 with exploit maturity unproven, but any Editor is enough, and credential theft outlasts the patch.

Who can reach it

Authenticated Grafana user with the Editor basic role (or any role carrying the contact point write/test permissions), over the network. Requires an outbound path from Grafana to an attacker-controlled host.

What to do

Upgrade to the Grafana release named in the advisory for CVE-2025-12141 and restart Grafana. Because the flaw leaks secrets rather than just granting access, rotate every credential stored in a contact point - Slack tokens, webhook URLs, API keys - after patching; patching alone does not undo prior exfiltration. Interim mitigation: strip contact point write and test permissions from the Editor role, and restrict Grafana's egress so a retargeted contact point cannot reach arbitrary hosts.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.