ID:11434 - Exploit for Prototype pollution in Kibana - CVE-2025-25014
Published: May 30, 2025
Kibana
Link to public exploit:
Vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper input validation within the machine learning and reporting endpoints. A remote privileged user can send a specially crafted HTTP request to the application, perform prototype pollution and execute arbitrary code in the context of Kibana.