CVE-2025-25014
A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.
- Affected products
- Kibana
- Elastic Kibana
- < 8.17.6, 8.18.0, 9.0.0
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 21.5% (97th percentile)
- Weakness
- CWE-1321
- NVD status
- Analyzed
- Published
- 2025-05-06
- Attack patterns
- CAPEC-242
CVE-2025-25014 at NVD
2 known exploits for CVE-2025-25014
Proof-of-concept code and exploit modules indexed by Sploitus