#VU108739 Prototype pollution in Kibana - CVE-2025-25014
Published: May 6, 2025 / Updated: May 30, 2025
Kibana
Elastic Stack
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper input validation within the machine learning and reporting endpoints. A remote privileged user can send a specially crafted HTTP request to the application, perform prototype pollution and execute arbitrary code in the context of Kibana.