CVE-2026-15583Disclosed before NVD
Grafana MCP server-side request forgery via X-Grafana-URL header
📋 Description
A vulnerability has been discovered in the mcp-grafana project (https://github.com/grafana/mcp-grafana) where a confused-deputy flaw allows an unauthenticated remote attacker to exfiltrate the server’s environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This vulnerability is classified as Server-Side Request Forgery (SSRF) and also enables credentialed SSRF against arbitrary internal services, including cloud metadata endpoints. Upgrade to a fixed version listed below.
🎯 Affected products1
- Grafana