Cross-site Scripting Vulnerability in Vega by Elastic
CVE-2025-68385

7.2HIGH

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
18 December 2025

What is CVE-2025-68385?

This vulnerability in Vega enables an authenticated user to inject malicious scripts into web pages via improper input neutralization. Consequently, when these scripts are executed in web browsers, they can compromise user data and session integrity, effectively enabling cross-site scripting (XSS) attacks. This implementation flaw bypasses previous mitigation measures, posing significant risks to users and organizations relying on Vega for their web applications.

Affected Version(s)

Kibana 7.0.0 <= 7.17.29

Kibana 8.0.0 <= 8.19.8

Kibana 9.0.0 <= 9.1.8

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-68385 : Cross-site Scripting Vulnerability in Vega by Elastic