Skip to main content
VerifiedExfiltration

GrafanaGhost, where stored data became an instruction and the assistant posted observability data to an external server

Noma Security disclosed in April 2026 that an indirect prompt injection stored inside an observability platform's own data, combined with a protocol relative URL that slipped past outbound request validation and a keyword bypass of the model guardrails, made the platform's AI assistant send data to an external server on its own, with nothing for the user to click.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AIL-2026-0019
Kind
Exfiltration
Jurisdiction
Global
Last verified
Added
  • The research states that because the exploit ignores model restrictions and operates autonomously, sensitive enterprise data can be leaked silently.
  • The injected instruction was stored inside the platform's own data, so the agent met it during normal work.
  • The outbound request validation was bypassed with a protocol relative URL, meaning a real control existed and was defeated rather than absent.
  • Exfiltration happened in the background with no suspicious link for the user to click.
  • The core issue was patched after coordinated disclosure.

Dimension by dimension

6 dimensions, each one stated, silent or open

Identity, Authorization, Limits, Human approval, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
Stored log content was read as instruction with no marker separating data from direction.Noma Security, GrafanaGhost, primary source, 7 April 2026.
AuthorizationSilent
The assistant queried what the user could query and applied it to an attacker's goal.Noma Security, GrafanaGhost, primary source, 7 April 2026.
LimitsSilent
A client side restriction on external requests was live and had to be defeated with a protocol relative URL, so the guard was real but insufficient.Noma Security, GrafanaGhost, primary source, 7 April 2026.
Human approvalSilent
The research states the exfiltration ran entirely in the background with nothing presented to the user.Noma Security, GrafanaGhost, primary source, 7 April 2026.
RevocationStated
The core issue was patched by the vendor after disclosure.Noma Security, GrafanaGhost, primary source, 7 April 2026.
AccountabilityStated
Named vendor, coordinated disclosure and a vendor response on the record.Noma Security, GrafanaGhost, primary source, 7 April 2026.

What it changes

For a team deploying an agent

Your own telemetry is untrusted input the moment an assistant reads it, because anything that writes a log line can write an instruction. The control to strengthen is limits, and specifically the URL validation on the outbound side: normalise and resolve every destination before the request, refuse protocol relative and redirecting targets, and hold the allowlist server side where a page cannot reach it.

Sources

What this record was verified against

  1. Noma Security, GrafanaGhostPrimary · 7 April 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0019 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), grafanaghost, where stored data became an instruction and the assistant posted observability data to an external server.
APA
GAGE (Global Academy of Generative-AI Education). (2026). GrafanaGhost, where stored data became an instruction and the assistant posted observability data to an external server. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0019-grafanaghost-observability-assistant-sent-data-out
MLA
"GrafanaGhost, where stored data became an instruction and the assistant posted observability data to an external server." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0019-grafanaghost-observability-assistant-sent-data-out.
Chicago
GAGE (Global Academy of Generative-AI Education). "GrafanaGhost, where stored data became an instruction and the assistant posted observability data to an external server." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0019-grafanaghost-observability-assistant-sent-data-out.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0019-grafanaghost-observability-assistant-sent-data-out

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for Global and every exfiltration record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.