Skip to content
Grafana LabsCVE-2026-19516

Grafana MCP Server: server-side request forgery

Critical9.1CVE-2026-19516 · Published Aug 11, 2026 · updated Aug 31, 2026

A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at internal, loopback, and link-local network services (including metadata endpoints) and read the responses, resulting in server-side request forgery. The fix for CVE-2026-15583 prevented the configured service-account token from being sent to unintended destinations but did not restrict the destinations themselves.

Grafana Labs advisory

Affected versions

PackageAffectedFixed in
Grafana MCP Server
Product
>= 0.0.0, <= 1.0.0No fix yet
mcp-grafana
Product
>= 0.0.0, <= 1.0.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-918

More Grafana Labs advisories

All Grafana Labs
Advisory
Grafana Labs Alloy: exposed files
High7.7Aug 27
Grafana Labs Clickhouse Datasource: cleartext transmission
Medium6.1Aug 27
Grafana: improper access control
Medium6.3Aug 26
Grafana OSS: cross-site scripting
Medium6.8Aug 24
Grafana: improper authorization
High7.1Aug 19
Grafana: information disclosure
Medium5.3Aug 17

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.