Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.
https://security.netapp.com/advisory/ntap-20211229-0004/
https://github.com/grafana/grafana/commit/c798c0e958d15d9cc7f27c72113d572fa58545ce
http://www.openwall.com/lists/oss-security/2021/12/10/4
http://www.openwall.com/lists/oss-security/2021/12/09/2
http://packetstormsecurity.com/files/165198/Grafana-Arbitrary-File-Reading.html
https://github.com/chengbochuan3/CVE-Learn
https://github.com/Lim-ahmin/CVE-2021-43798
https://github.com/Asbawy/GrafTraverse-CVE-2021-43798
https://github.com/DiegoRodriguez-GL/bigschool-ciberseguridad
https://github.com/THU-HJY/CVE-Honeypot
https://github.com/s4mjx/Portscanner-py
https://github.com/kikechans/Grafana-LFI-Exploit-CVE-2021-43798-
https://github.com/Shoxake17/CVE-2021-43798
https://github.com/Zierax/Grafana-Final-Scanner
https://github.com/strikoder/Grafana-Password-Decryptor
https://github.com/f3d0rq/CVE-2021-43798
https://github.com/Bhanunamikaze/VaktScan
https://github.com/AnonUsenix/LLM_Agent_Cybersecurity_Forensic
https://github.com/PuddinCat/GithubRepoSpider
https://github.com/suljov/Grafana-LFI-exploit
https://github.com/g1san/Agents-for-Vulnerable-Dockers-and-related-Benchmarks
https://github.com/monke443/CVE-2021-43798
https://github.com/ravi5hanka/CVE-2021-43798-Exploit-for-Windows-and-Linux
https://github.com/wezoomagency/GrafXploit
https://github.com/sazzad1337/Grafana-CVE-2021-43798
https://github.com/ShadowByte1/CVES
https://github.com/Sic4rio/Grafana-Decryptor-for-CVE-2021-43798
https://github.com/mauricelambert/LabAutomationCVE-2021-43798
https://github.com/YourKeeper/SunScope
https://github.com/0bfxgh0st/cve-rebuilds
https://github.com/kh4sh3i/Grafana-CVE
https://github.com/truonghuuphuc/OWASP-ZAP-Scripts
https://github.com/luisfelipe146/CVEpedia
https://github.com/Jroo1053/GrafanaDirInclusion
https://github.com/k3rwin/CVE-2021-43798-Grafana-
https://github.com/k3rwin/CVE-2021-43798-Grafana
https://github.com/LongWayHomie/CVE-2021-43798
https://github.com/fanygit/Grafana-CVE-2021-43798Exp
https://github.com/zzbrock/Grafana_POC-CVE-2021-43798
https://github.com/culprits/Grafana_POC-CVE-2021-43798
https://github.com/broc999/Grafana_POC-CVE-2021-43798
https://github.com/Mo0ns/Grafana_POC-CVE-2021-43798
https://github.com/MzzdToT/Grafana_fileread
https://github.com/lfz97/CVE-2021-43798-Grafana-File-Read
https://github.com/j-jasson/CVE-2021-43798-grafana_fileread
https://github.com/kenuosec/grafanaExp
https://github.com/A-D-Team/grafanaExp
https://github.com/Mr-xn/CVE-2021-43798
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-43798
https://grafana.com/blog/2021/12/08/an-update-on-0day-cve-2021-43798-grafana-directory-traversal/
https://github.com/grafana/grafana/security/advisories/GHSA-8pjx-jj86-j47p
Published: 2021-12-07
Updated: 2026-06-17
Known Exploited Vulnerability (KEV)
Base Score: 5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N
Severity: Medium
Base Score: 7.5
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity: High
EPSS: 0.88503
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability Being Monitored