CyberRota Analysis
AI-GeneratedGrafana MCP Server is vulnerable to a confused-deputy flaw that allows unauthenticated remote attackers to exfiltrate the service-account token by manipulating the X-Grafana-URL request header. This vulnerability also facilitates server-side request forgery (SSRF) attacks against internal services, potentially exposing sensitive cloud metadata. Organizations using Grafana MCP Server should prioritize patching this vulnerability to mitigate the risk of unauthorized access and data leakage.
Original NVD Description
A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.