Unrated severityOSV Advisory· Published Dec 18, 2025· Updated Dec 19, 2025
Kibana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-68387
Description
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a vulnerability a function handler in the Vega AST evaluator.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.