Critical severity9.1NVD Advisory· Published May 6, 2025· Updated Jun 17, 2026
CVE-2025-25014
CVE-2025-25014
Description
A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- osv-coords2 versions
>= 8.3.0, < 8.18.1+ 1 more
- (no CPE)range: >= 8.3.0, < 8.18.1
- (no CPE)range: >= 8.3.0, < 8.17.6
Patches
Vulnerability mechanics
References
1- discuss.elastic.co/t/kibana-8-17-6-8-18-1-or-9-0-1-security-update-esa-2025-07/377868nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.