CVE-2025-25014: Kibana arbitrary code execution via prototype pollution
Published May 6, 2025
·Updated
A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.
Affected Software
4 affected components
Elastic Kibana
Elastic Kibana>=8.3.0<8.17.6
Elastic Kibana=8.18.0
Elastic Kibana=9.0.0
Remediation
Event History
May 6, 2025
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25014?
CVE-2025-25014 is a critical severity vulnerability that allows arbitrary code execution.
2
How do I fix CVE-2025-25014?
To mitigate CVE-2025-25014, you should upgrade to the latest patched version of Kibana as recommended by Elastic.
3
What versions of Kibana are affected by CVE-2025-25014?
CVE-2025-25014 impacts multiple versions of Kibana including versions prior to the latest security updates.
4
How does CVE-2025-25014 impact Kibana users?
Users of Kibana are at risk of unauthorized access and execution of arbitrary code due to this vulnerability.
5
What steps can I take to protect my Kibana installation from CVE-2025-25014?
In addition to upgrading, ensure your Kibana instance is behind a firewall and monitor for suspicious activity.