Vulnerability CVE-2025-25014 (CVSS 9.1): Prototype Pollution in Kibana Opens Door to Code Execution Ddos May 7, 2025 2 minutes read 0 π Access to This Vulnerability Report Requires Support This article is available to verified supporters only - contribute to read the full report Or choose another support option: Support via PayPal Support via BMC Share this article: Facebook Post LinkedIn Telegramcve-2025-25014-cvss-9-1-prototype-pollution-in-kibana-opens-door-to-code-execution/')" style="display: inline-flex; align-items: center; justify-content: center; gap: 8px; margin-right: 10px; margin-bottom: 10px; padding: 8px 16px; color: #ffffff; text-decoration: none; border-radius: 4px; font-size: 14px; font-weight: 500; transition: background-color 0.2s; background-color: #475569; border: none; cursor: pointer; font-family: inherit;"> Copy Link Related posts: Kibana Code Injection Vulnerability: Prototype Pollution Threat (CVE-2024-12556) CVE-2024-21512: MySQL2 Vulnerability Puts Millions of Downloads at Risk CVE-2025-25015 (CVSS 9.9): Critical Code Execution Vulnerability Patched in Elastic Kibana High-Severity Flaw in Kibana: Unauthorized Access Possible in Synthetic Monitoring! Elastic APM Server & Beats Have Local Privilege Escalation Flaws Tags: Arbitrary Code Execution CVE-2025-25014 Elastic Kibana Prototype Pollution Vulnerability Leave a Reply Cancel replyLogged in as . Edit your profile. Log out? Required fields are marked *Comment *