{"id":"CVE-2024-9264","aliases":["BIT-grafana-2024-9264","GHSA-q99m-qcv4-fpm7","GO-2024-3215"],"url":"https://o3.security/vulnerability/CVE-2024-9264","summary":"Grafana SQL Expressions allow for remote code execution","details":"The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack.  The `duckdb` binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distributions.","published":"2024-10-18T03:20:52.489Z","modified":"2026-08-12T03:51:31.616368112Z","cvss":null,"epss":{"score":0.94864,"percentile":0.99854,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":7,"affectedPackages":[{"ecosystem":"Go","name":"github.com/grafana/grafana","fixedVersion":"11.0.6+security-01"},{"ecosystem":"Go","name":"github.com/grafana/grafana","fixedVersion":"11.1.7+security-01"},{"ecosystem":"Go","name":"github.com/grafana/grafana","fixedVersion":"11.2.2+security-01"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/grafana/grafana/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/9xxx/CVE-2024-9264.json"},{"type":"ADVISORY","url":"https://grafana.com/security/security-advisories/cve-2024-9264/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-9264"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250314-0007/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:31.616368112Z"}}