Grafana disclosed a cross-site scripting (XSS) vulnerability in the Geomap MapLibre component of Grafana OSS. Affected versions are 12.3.0 through 12.4.10, 13.0.0 through 13.0.8, 13.1.0 through 13.1.5, and 13.2.0 through 13.2.1.
The Canadian Centre for Cyber Security and Guyana National CIRT advised administrators to review Grafana’s security advisory and apply available updates. The published notices did not specify a CVE identifier, severity rating, exploitation status, technical exploitation details, or the remediated release versions.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-936, warning that Grafana OSS was affected by the Geomap MapLibre XSS issue and directing administrators to review Grafana advisories and apply available updates.
Grafana published a security advisory for a cross-site scripting vulnerability associated with the Geomap MapLibre component. It identified affected Grafana OSS versions 12.3.0–12.4.10, 13.0.0–13.0.8, 13.1.0–13.1.5, and 13.2.0–13.2.1.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecirt.gy
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.