GrafanaGhost, where stored data became an instruction and the assistant posted observability data to an external server
Noma Security disclosed in April 2026 that an indirect prompt injection stored inside an observability platform's own data, combined with a protocol relative URL that slipped past outbound request validation and a keyword bypass of the model guardrails, made the platform's AI assistant send data to an external server on its own, with nothing for the user to click.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AIL-2026-0019
- Kind
- Exfiltration
- Jurisdiction
- Global
- Last verified
- Added
- The research states that because the exploit ignores model restrictions and operates autonomously, sensitive enterprise data can be leaked silently.
- The injected instruction was stored inside the platform's own data, so the agent met it during normal work.
- The outbound request validation was bypassed with a protocol relative URL, meaning a real control existed and was defeated rather than absent.
- Exfiltration happened in the background with no suspicious link for the user to click.
- The core issue was patched after coordinated disclosure.
Dimension by dimension
6 dimensions, each one stated, silent or open
Identity, Authorization, Limits, Human approval, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- Stored log content was read as instruction with no marker separating data from direction.Noma Security, GrafanaGhost, primary source, 7 April 2026.
- AuthorizationSilent
- The assistant queried what the user could query and applied it to an attacker's goal.Noma Security, GrafanaGhost, primary source, 7 April 2026.
- LimitsSilent
- A client side restriction on external requests was live and had to be defeated with a protocol relative URL, so the guard was real but insufficient.Noma Security, GrafanaGhost, primary source, 7 April 2026.
- Human approvalSilent
- The research states the exfiltration ran entirely in the background with nothing presented to the user.Noma Security, GrafanaGhost, primary source, 7 April 2026.
- RevocationStated
- The core issue was patched by the vendor after disclosure.Noma Security, GrafanaGhost, primary source, 7 April 2026.
- AccountabilityStated
- Named vendor, coordinated disclosure and a vendor response on the record.Noma Security, GrafanaGhost, primary source, 7 April 2026.
What it changes
For a team deploying an agent
Your own telemetry is untrusted input the moment an assistant reads it, because anything that writes a log line can write an instruction. The control to strengthen is limits, and specifically the URL validation on the outbound side: normalise and resolve every destination before the request, refuse protocol relative and redirecting targets, and hold the allowlist server side where a page cannot reach it.
Sources
What this record was verified against
- Noma Security, GrafanaGhostPrimary · 7 April 2026
Related
Records that sit beside this one
ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain
United States · verified 15 September 2026
Noma Security states that an allowlisted domain had expired and become available for purchase, and that the researchers bought it.
SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out
United States · verified 15 September 2026
The research states that the copilot interprets the query parameter as instructions and searches the victim's mailbox.
Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident?
Global · verified 15 September 2026
Every incident record in this dataset that involves a destructive or irreversible action records human approval as absent, bypassed or uninformed.
Does any published standard require an agent to hold an identity distinct from the person it acts for?
Global · verified 15 September 2026
The Model Context Protocol authorization specification states that clients must implement resource indicators for OAuth so that a token names the resource it is for.
Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?
Global · verified 15 September 2026
The AI Incident Database describes itself as indexing the collective history of harms or near harms realised in the real world by deployed AI systems.
Who is liable when an agent commits its principal to something false or binding?
Global · verified 15 September 2026
The Canadian tribunal decision is a small claims level decision and is not binding precedent on other courts.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0019 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), grafanaghost, where stored data became an instruction and the assistant posted observability data to an external server.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). GrafanaGhost, where stored data became an instruction and the assistant posted observability data to an external server. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0019-grafanaghost-observability-assistant-sent-data-out
- MLA
- "GrafanaGhost, where stored data became an instruction and the assistant posted observability data to an external server." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0019-grafanaghost-observability-assistant-sent-data-out.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "GrafanaGhost, where stored data became an instruction and the assistant posted observability data to an external server." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0019-grafanaghost-observability-assistant-sent-data-out.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0019-grafanaghost-observability-assistant-sent-data-out
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for Global and every exfiltration record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.