Reads /etc/passwd through Grafana's plugin static file serving, which fails to sanitize path traversal sequences in the plugin ID path.
Is your app exploitable through CVE-2021-43798?