CVE-2024-8986: Grafana-Plugin-SDK-Go Grafana Plugin SDK
Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.
The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running `git remote get-url origin`. If credentials are included in the repository URI (for instance, to allow for fetching of private dependencies), the final binary will contain the full URI, including said credentials.
Affected products
- Grafana-Plugin-SDK-Go Grafana Plugin SDK: from 0.106.0, up to and including 0.249.0
Published 2024-09-19. Last modified 2026-06-17.