Vulnerability Description
A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Kibana | >= 8.3.0, < 8.17.6 |
Related Weaknesses (CWE)
References
- https://discuss.elastic.co/t/kibana-8-17-6-8-18-1-or-9-0-1-security-update-esa-2PatchVendor Advisory
FAQ
What is CVE-2025-25014?
CVE-2025-25014 is a vulnerability with a CVSS score of 9.1 (CRITICAL). A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.
How severe is CVE-2025-25014?
CVE-2025-25014 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-25014?
Check the references section above for vendor advisories and patch information. Affected products include: Elastic Kibana.