CVE-2025-68387: Kibana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a vulnerability a function handler in the Vega AST evaluator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68387?
CVE-2025-68387 is classified with a high severity due to its potential to allow unauthenticated users to execute malicious scripts.
How do I fix CVE-2025-68387?
To fix CVE-2025-68387, update to the latest version of Kibana that addresses the cross-site scripting vulnerability.
What type of vulnerability is CVE-2025-68387?
CVE-2025-68387 is a Cross-Site Scripting (XSS) vulnerability caused by improper neutralization of input.
Who is affected by CVE-2025-68387?
CVE-2025-68387 affects users of Kibana versions prior to the security update addressing this issue.
Can CVE-2025-68387 be exploited remotely?
Yes, CVE-2025-68387 can be exploited remotely by an attacker through crafted web content served to a browser.