All verified exploits

CVE-2025-11539 Image Renderer Arbitrary File Write / RCE

Deterministic critical Grafana Added cve-verified-cve-2025-11539

Confirms the Grafana Image Renderer's /render endpoint accepts path traversal in the filePath parameter with the default auth token, allowing arbitrary file writes that lead to remote code execution. Affects versions 1.0.0 through 4.0.16.

Is your app exploitable through CVE-2025-11539?

Scan your domain free