Kibana Unrestricted File Upload Vulnerability Leading to Cross-Site Scripting

Vulnerability

A vulnerability in Kibana allowing unrestricted upload of files with dangerous types can lead to arbitrary execution of JavaScript in a victim's browser, resulting in cross-site scripting (XSS). This issue arises from the ability to upload crafted HTML and JavaScript files. The vulnerability affects Kibana versions 7.17.6 prior to 7.17.24 and 8.4.0 prior to 8.11.4. To exploit this vulnerability, an attacker must have access to the Synthetics app or the ability to write to the synthetics indices.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where an attacker can execute malicious JavaScript in the context of the victim's browser.

Remediation

Users can upgrade to Kibana versions 7.17.24 or 8.12.0 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
1.7
exploitability
4.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.