The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack. The `duckdb` binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distributions.
PoC: CVE-2024-9264
Exploit for Grafana arbitrary file-read (CVE-2024-9264)
PoC: CVE-2024-9264-RCE-Exploit
Grafana RCE exploit (CVE-2024-9264)
PoC: CVE-2024-9264-in-Grafana-11.x
Vulnerability Exploitation using tools Penetration Testing, Grafana, Docker, Kali Linux.
PoC: CVE-2024-9264
CVE-2024-9264 Grafana SQL Expressions DuckDB LFI/RCE PoC
PoC: day05-grafana-sqlexpr-lab
Grafana SQL Expressions → DuckDB LFI (CVE-2024-9264)
PoC: grafana-CVE-2024-9264
Grafana image with DuckDB binary present vulnerable to exploit CVE-2024-9264
PoC: CVE-2024-9264
Authenticated RCE in Grafana (v11.0) via SQL Expressions - PoC Exploit
PoC: CVE-2024-9264
Grafana RCE
PoC: CVE-2024-9264
A go implementation for CVE-2024-9264 which effect grafana versions 11.0.x, 11.1.x, and 11.2.x.
PoC: CVE-2024-9264
Exploit for Grafana arbitrary file-read (CVE-2024-9264)
PoC: File-Read-CVE-2024-9264
File Read Proof of Concept for CVE-2024-9264
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free