Kibana arbitrary code execution via prototype pollution
53Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.1epss 21%
from disclosure to weapon18 days
Published on NVDMay 6
1st PoC+18d
exploitation probability
21%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
In short
A flaw in Kibana allows attackers to manipulate how the application creates objects, leading to arbitrary code execution. This happens through specially crafted requests to machine learning and reporting features, letting attackers run any code on the server.
Technical detail
Prototype pollution vulnerability in Kibana's object handling allows attackers to inject malicious properties into prototype chains via crafted HTTP requests to machine learning and reporting endpoints, resulting in arbitrary code execution with server privileges. Attack requires network access to affected endpoints; no authentication bypass is needed if endpoints are exposed.
Summary generated and translated by AI from the official description.
A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected products
Elastic · Kibanapublic PoCs found — 1
githubgithub.com/davidxbors/CVE-2025-25014★ 1⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.