Cross-site Scripting Vulnerability in Vega by Elastic
CVE-2025-68385
7.2HIGH
What is CVE-2025-68385?
This vulnerability in Vega enables an authenticated user to inject malicious scripts into web pages via improper input neutralization. Consequently, when these scripts are executed in web browsers, they can compromise user data and session integrity, effectively enabling cross-site scripting (XSS) attacks. This implementation flaw bypasses previous mitigation measures, posing significant risks to users and organizations relying on Vega for their web applications.
Affected Version(s)
Kibana 7.0.0 <= 7.17.29
Kibana 8.0.0 <= 8.19.8
Kibana 9.0.0 <= 9.1.8