# Issue with Node.js Vulnerabilities (CVE-2025) in Kibana 8.18.0

**URL:** <https://discuss.elastic.co/t/issue-with-node-js-vulnerabilities-cve-2025-in-kibana-8-18-0/378905>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [June 5, 2025, 10:48am UTC](https://discuss.elastic.co/t/issue-with-node-js-vulnerabilities-cve-2025-in-kibana-8-18-0/378905 "2025-06-05T10:48:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![debbbuu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debbbuu/32/144975_2.png) [@debbbuu](https://discuss.elastic.co/u/debbbuu)\
**Post date:** [June 5, 2025, 10:48am UTC](https://discuss.elastic.co/t/issue-with-node-js-vulnerabilities-cve-2025-in-kibana-8-18-0/378905/1 "2025-06-05T10:48:34Z")

</div>

Hi,

As part of the vulnerability assessment (VA) scan on our ELK servers, we identified that the Node.js version is affected by multiple vulnerabilities. We are using a self-managed cluster.

**Current Kibana Version:** 8.18.0  
**Path:** /usr/share/kibana/node/glibc-217/bin/node  
**Installed Node.js Version:** 20.18.2

The reported CVE IDs are:

- CVE-2025-23165
- CVE-2025-23166
- CVE-2025-23167

Our security team has suggested upgrading to an Node.js version greater than 20.19.2 / 22.15.1 / 23.11.1 / 24.0.2 or later.

How to check which Kibana version has which Node.js version?

Suggest if we have to upgrade the Kibana version to have latest Node.js. _(This approach isn’t ideal, as it would require manual intervention each time a new VA / version is discovered.)_

I would appreciate any guidance on this matter.

Thanks,  
Suraj

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 5, 2025, 11:32am UTC](https://discuss.elastic.co/t/issue-with-node-js-vulnerabilities-cve-2025-in-kibana-8-18-0/378905/2 "2025-06-05T11:32:15Z")

</div>

Thank you for your report.

Elastic's security reporting guidelines are available at [Security issues | Elastic](https://www.elastic.co/community/security).

Per those guidelines, all reports of potential security issues or vulnerabilities should be sent via email to [security@elastic.co](mailto:security@elastic.co).

We are unable to discuss potential issues of this nature here. Please send your report to the email address above, where it can be appropriately handled.

---

<div class="post-metadata">

**Author:** ![Khalid\_Safi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khalid_safi/32/144598_2.png) [@Khalid\_Safi](https://discuss.elastic.co/u/Khalid_Safi)\
**Post date:** [August 12, 2025, 11:36am UTC](https://discuss.elastic.co/t/issue-with-node-js-vulnerabilities-cve-2025-in-kibana-8-18-0/378905/3 "2025-08-12T11:36:45Z")

</div>

@debbbuu. Did you find any solution?. I am also in the same situation

---

<div class="post-metadata">

**Author:** ![debbbuu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debbbuu/32/144975_2.png) [@debbbuu](https://discuss.elastic.co/u/debbbuu)\
**Post date:** [September 10, 2025, 8:49am UTC](https://discuss.elastic.co/t/issue-with-node-js-vulnerabilities-cve-2025-in-kibana-8-18-0/378905/4 "2025-09-10T08:49:09Z")

</div>

Hi @Khalid_Safi,

After digging through quite a few articles on upgrading Node.js version in Kibana, I found that there isn't really a straightforward way to do it. Most sources mention that manually upgrading Node.js can cause issues due to internal dependencies within Kibana.

That being said, I came across a helpful [GitHub link](https://github.com/elastic/kibana/blob/v8.18.0/package.json) that lists different Kibana versions. In each version’s `package.json` file, you can find the required Node.js version under the `engines.node` field. This makes it easier to see which Node.js version is tied to which Kibana release. (Refer attached screenshot for reference)

So, the best (and safest) way to address Node.js vulnerabilities in Kibana is simply to upgrade Kibana itself to a version that includes a more recent Node.js version.

Hope this helps!

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/7/b7a232a642b6dd720c0238a6d78ca58041ca697a.png)
