Cross-site scripting in prometheus - #VU128366
Published: April 28, 2026
prometheus
Prometheus
Description
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the browser of a Prometheus user.
The vulnerability exists due to cross-site scripting in the histogram heatmap chart view of the legacy Prometheus web UI when rendering crafted histogram bucket label values in axis tick mark labels. A remote attacker can inject crafted metrics to execute arbitrary JavaScript in the browser of a Prometheus user.
Only instances with the legacy web UI enabled via the --enable-feature=old-ui flag are vulnerable.