References https://grafana.com/security/security-advisories/cve-2025-11539/ https://cn-sec.com/archives/4564878.html https://zeropath.com/blog/cve-2025-11539-grafana-image-renderer-rce-summary https://cybersecuritywriteups.com/render-unto-risk-cve-2025-11539-and-the-fragility-of-grafanas-image-renderer-5acb10358c48 https://www.bleepingcomputer.com/news/security/grafana-releases-critical-security-update-for-image-renderer-plugin/ https://cn-sec.com/archives/tag/grafana/page/2
Related VulnerabilitiesPoCgrafana-loki-api-exposure: Grafana Loki - Unauthenticated API AccessPoCCVE-2026-20896: Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Authentication BypassPoC用友A++ /ma/emp/maEmp/showImage 文件读取漏洞Grafana /api/ds/query DuckDB SQL 注入漏洞(CVE-2024-9264)天地伟业 Easy7 /Easy7/rest/downLoad/downLoadImage 文件读取漏洞PoCCVE-2026-27771: Gitea Container Registry - Unauthorized Private Image Access鼎游票务系统 /system/ImageViewServlet 文件读取漏洞WordPress WP Responsive Images /wp-responsive-images/image_handler.php 文件读取漏洞(CVE-2026-1557)PoCSmanga动漫管理平台 /php/get-image-list.php 命令执行漏洞Artica Proxy /images.listener.php 文件读取漏洞(CVE-2024-2053)PoC天地伟业Easy7 /Easy7/rest/file/uploadLedImage 文件上传漏洞天地伟业Easy7 uploadLedImage 文件上传漏洞PoC天地伟业Easy7 /Easy7/apps/WebService/UploadOwnerImage.jsp 文件上传漏洞