Sploitus

CVE-2025-25014

2 known exploits for CVE-2025-25014

A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.

Affected products
Kibana
Elastic Kibana
< 8.17.6, 8.18.0, 9.0.0
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
21.5% (97th percentile)
Weakness
CWE-1321
NVD status
Analyzed
Published
2025-05-06
Attack patterns
CAPEC-242
CVE-2025-25014 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2025-25014

Proof-of-concept code and exploit modules indexed by Sploitus