
Proof-of-concept client and Docker lab reproducing CVE-2026-15583, an unauthenticated confused-deputy SSRF in Grafana MCP Server that leaks service-account tokens via X-Grafana-URL.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected] · CVE-2026-15583
Grafana MCP Server 0.17.0 - Grafana Labs
I am @abraxas_null. Loopback lab. The client is CVE-2026-15583-Abraxas-Labs.py.
Confused deputy. Unauthenticated MCP HTTP takes X-Grafana-URL from the request and the service-account token from the environment, then GET {url}/api/frontend/settings with Authorization: Bearer. Empty X-Grafana-Service-Account-Token falls back to env. Fixed in 0.17.1 by not sending the configured token to unintended destinations.
| CVE | CVE-2026-15583 · CVE.org |
| CWE | CWE-918 |
| CVSS | High: 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
| Product | Grafana MCP Server |
| Affected | all versions through 0.17.0 (inclusive) |
| Patched | 0.17.1 and later |
| Auth | unauthenticated |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only |
POST /mcp or GET /sse with X-Grafana-URL pointing at a collector you control. The server ships GRAFANA_SERVICE_ACCOUNT_TOKEN (or GRAFANA_API_KEY) to you. That is credentialed SSRF plus token theft. Lab oracle is the witness token in the collector Authorization header.
I mapped extractKeyGrafanaInfoFromReq / ExtractGrafanaInfoFromHeaders, then NewGrafanaClient fetchPublicURL, then AuthRoundTripper. Stood up mcp-grafana 0.17.0 with a loopback collector.
Fail-controls already in the lab: eval/base64/system is not the witness; a reverse shell is not the witness; 0.17.1 must not send the env token to the collector.
Port 18099. mcp-grafana 0.17.0. SSE or streamable-http reachable. Env token set. Collector on the compose network.
Target only 127.0.0.1:18099 (or the loopback you bound).
cd lab
docker compose up --force-recreate
python3 ../CVE-2026-15583-Abraxas-Labs.py
Witness: Collector Authorization header contains GHSA15583-WITNESS.
Ways to lose without learning anything:
Update Grafana MCP Server to 0.17.1 or newer. Re-run CVE-2026-15583-Abraxas-Labs.py against the patched build: the collector must not see the env token.
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
GNU Affero GPL v3.0. See LICENSE.
The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.