CVE-2025-25015: Kibana arbitrary code execution via prototype pollution
Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2 , this is only exploitable by users that have roles that contain all the following privileges: fleet-all, integrations-all, actions:execute-advanced-connectors
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25015?
CVE-2025-25015 is a critical vulnerability that allows for arbitrary code execution due to prototype pollution in Kibana.
How do I fix CVE-2025-25015?
To fix CVE-2025-25015, upgrade Kibana to version 8.17.3 or later.
Who is affected by CVE-2025-25015?
CVE-2025-25015 affects users with the Viewer role in Kibana versions 8.15.0 to 8.17.1 and 8.17.1 to 8.17.2.
What types of attacks can exploit CVE-2025-25015?
CVE-2025-25015 can be exploited through crafted file uploads and specially crafted HTTP requests.
Is CVE-2025-25015 a local or remote vulnerability?
CVE-2025-25015 is a remote vulnerability that can be exploited by malicious users over the network.