
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68385 is a stored/reflected Cross-Site Scripting (XSS) vulnerability in Elastic Kibana affecting its Vega visualization integration. An authenticated user can embed malicious scripts in content served to web browsers by exploiting a method in Vega that bypasses a previously implemented XSS mitigation. The vulnerability was disclosed on December 18, 2025, and affects Kibana versions 7.0.0–7.17.29, 8.0.0–8.19.8, 9.0.0–9.1.8, and 9.2.0–9.2.2. It carries a CVSS v3.1 base score of 6.1 (Medium) (Red Hat Advisory, Elastic Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically within Kibana's Vega visualization component. An authenticated attacker can craft a Vega specification or chart definition that invokes a particular Vega method, injecting malicious JavaScript that circumvents an existing XSS sanitization/mitigation layer. The attack vector is network-based, requires low attack complexity, and necessitates user interaction (a victim browsing to the malicious content), with the scope changed to affect other users' browser sessions. The vulnerability is classified under CAPEC-63 (Cross-Site Scripting) (Red Hat Bugzilla, Elastic Advisory).
Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the browsers of other Kibana users who view the malicious visualization. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of victims, and exfiltration of sensitive data accessible within the Kibana interface. The changed scope means the impact extends beyond the attacker's own session to affect other authenticated users, including potentially privileged administrators (Red Hat Advisory, Elastic Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Red Hat Advisory). The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated attacker with access to create or modify Vega visualizations in Kibana.
<script> injection or event handler) within the chart definition.eval, fetch, XMLHttpRequest, document.cookie, <script> tags, or on* event handlers).Elastic has released patched versions addressing this vulnerability: Kibana 8.19.9, 9.1.9, and 9.2.3. Users running versions 7.x through the affected 8.x and 9.x ranges should upgrade to the appropriate fixed release immediately (Elastic Advisory). As interim mitigations, administrators should restrict Vega visualization creation permissions to trusted users only, implement a strict Content Security Policy (CSP), and monitor for suspicious visualization content. Additional input validation and output encoding controls should be verified as part of defense-in-depth.
Security news outlets including GBHackers and SecurityOnline.info covered the vulnerability, with SecurityOnline describing it as "visualizations weaponized" via Vega charts (SecurityOnline, GBHackers). A blog post on cryptobivash.code.blog characterized the issue as a "0-day" that "bypasses XSS defenses via weaponized Vega charts," though this framing is somewhat sensationalized given that a patch was simultaneously released (Cryptobivash Blog). Elastic's official advisory was straightforward, noting the bypass of a prior Vega XSS mitigation and providing fixed version numbers without additional commentary.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."