Researchers at Noma Security disclosed GrafanaGhost, a vulnerability in Grafana that allowed attackers to silently exfiltrate sensitive data by abusing the platform’s AI-assisted processing of user-controlled input. The attack required no credentials or user interaction and began with a crafted external URL path or query parameter that exploited weaknesses in domain validation, AI guardrails, and content security controls. Noma said the chain could make Grafana treat attacker-controlled external resources as trusted and send sensitive operational, financial, infrastructure, or customer data to an attacker-controlled server, including through image requests.
Grafana Labs validated the findings after responsible disclosure and released a fix. Researchers said the attack was especially concerning because the malicious behavior could appear as normal AI activity and evade traditional monitoring, highlighting how indirect prompt injection can bypass multiple defensive layers in enterprise platforms. Industry reaction underscored both the growing risk from AI-specific attack surfaces and the debate over practical exploitability in hardened deployments with stronger network controls.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Noma Security publicly disclosed GrafanaGhost, describing how indirect prompt injection, crafted external URL paths or query parameters, and protocol-relative URL handling could be chained to make Grafana send sensitive data to an attacker-controlled server.
Grafana Labs issued a fix to address the validated GrafanaGhost vulnerability, which involved weaknesses in areas including domain validation, AI guardrails, and content security controls.
After Noma Security reported the findings through responsible disclosure, Grafana Labs confirmed the vulnerability affecting Grafana's AI-related processing and defensive controls.
Noma Security identified a vulnerability chain in Grafana, later dubbed GrafanaGhost, that abuses AI-assisted processing of user-controlled input to bypass multiple defenses and exfiltrate sensitive data without credentials or user interaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcehackread.com
Open sourcecyberscoop.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.