---
id: CVE-2025-37732
title: >-
  Improper neutralization of input during web page generation ('Cross-site
  Scripting') (CWE-79) allows an authenticated user to render HTML tags within a
  user’s browser via the integration package upload functionality
summary: >-
  Improper neutralization of input during web page generation ('Cross-site
  Scripting') (CWE-79) allows an authenticated user to render HTML tags within a
  user’s browser via the integration package upload functionality. This issue is
  relate…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: elastic
product: kibana
affected:
  - 'kibana >= 7.0.0, <= 7.17.29'
  - 'kibana >= 8.0.0, < 8.19.8'
  - 'kibana >= 9.0.0, < 9.1.8'
  - 'kibana >= 9.2.0, < 9.2.2'
patched:
  - kibana 9.2.2
published: '2025-12-15'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-37732'
references:
  - url: >-
      https://discuss.elastic.co/t/kibana-8-19-8-9-1-8-and-9-2-2-security-update-esa-2025-28/384064
    label: security@elastic.co
tags:
  - nvd
epss: 0.00181
epssPercentile: 0.06969
ingestedAt: '2026-10-07T19:44:15.684Z'
---

## Overview

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025-17 (CVE-2025-25018) bypassing that fix to achieve HTML injection.

## Affected

- `kibana >= 7.0.0, <= 7.17.29`
- `kibana >= 8.0.0, < 8.19.8`
- `kibana >= 9.0.0, < 9.1.8`
- `kibana >= 9.2.0, < 9.2.2`

## Remediation

Upgrade past the affected range:

- `kibana 9.2.2`
