Kibana 8.19.9 – Multiple HIGH severity dependency vulnerabilities (npm & OS packages)

Product Details

  • Product: Kibana

  • Version: 8.19.9

  • Deployment: Self-managed / Community

  • Build type: Official Elastic Docker / tar distribution

  • Issue category: Third-party dependency vulnerabilities


:stop_sign: Identified Vulnerabilities

1. LangChain – Serialization Injection

  • Package: @langchain/core

  • Installed: 0.3.57

  • Fixed in: 0.3.80

  • GHSA: GHSA-r399-636x-v7f6

  • Severity: HIGH

  • Impact: Potential secret extraction via unsafe serialization

2. LangChain (core package)

  • Package: langchain

  • Installed: 0.3.15

  • Fixed in: 0.3.37

  • GHSA: GHSA-r399-636x-v7f6

  • Severity: HIGH

3. expr-eval – Prototype Pollution

  • Package: expr-eval

  • Installed: 2.0.2

  • GHSA: GHSA-8gw3-rxh4-v6jx

  • Severity: HIGH

  • Impact: Prototype pollution via crafted expressions

4. expr-eval – Unsafe function execution

  • Package: expr-eval

  • Installed: 2.0.2

  • GHSA: GHSA-jc85-fpwf-qm7x

  • Severity: HIGH

5. systeminformation – Command Injection (Windows)

  • Package: systeminformation

  • Installed: 5.23.8

  • Fixed in: 5.27.14

  • GHSA: GHSA-wphj-fx3q-84ch

  • Severity: HIGH

6. gpgv – OS package vulnerability

  • Package: gpgv

  • Installed: 2.4.4-2ubuntu17.3

  • Fixed in: 2.4.4-2ubuntu17.4

  • CVE: CVE-2025-68973

  • Severity: HIGH


:bullseye: Questions for Elastic Security Team

  1. Are these vulnerabilities considered reachable / exploitable in Kibana 8.19.9?

  2. Will these be addressed in the next 8.19.x patch release?

  3. Is there an estimated remediation timeline?

  4. Are there recommended mitigations until a patch is released?

Welcome!

Is it a post generated with AI?

Anyway, thank you for your report.

Elastic's security reporting guidelines are available at Product Security at Elastic | Elastic .

Per those guidelines, all reports of potential security issues or vulnerabilities should be sent via email to security@elastic.co.

We are unable to discuss potential issues of this nature here. Please send your report to the email address above, where it can be appropriately handled.

1 Like