> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# CVE-2025-25015: Kibana arbitrary code execution via prototype pollution
- URL: https://darkwebinformer.com/cve-2025-25015-kibana-arbitrary-code-execution-via-prototype-pollution/
- Published: 2025-03-05T20:06:56.000Z
- Updated: 2025-09-04T22:23:35.000Z
- Author: Dark Web Informer
- Tags: Vulnerabilities

🚨 Critical Security Vulnerability  
🆔 CVE-2025-25015  
💣 CVSS Score: 9.9  
📅 Published Date: 2025-03-05

⚠️ Details: Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests.  
In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2 , this is only exploitable by users that have roles that contain all the following privileges: fleet-all, integrations-all, actions:execute-advanced-connectors

🛠 References:  
🔗 NIST: <https://nvd.nist.gov/vuln/detail/CVE-2025-25015>  
🔗 Elastic: <https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441>