CVE-2025-48985 Affecting kibana-8.18 package, versions *


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.17% (38th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-MINIMOSLATEST-KIBANA818-13864779
  • published10 Nov 2025
  • disclosed7 Nov 2025

Introduced: 7 Nov 2025

CVE-2025-48985  (opens in a new tab)

How to fix?

There is no fixed version for Minimos:latest kibana-8.18.

NVD Description

Note: Versions mentioned in the description apply only to the upstream kibana-8.18 package and not the kibana-8.18 package as distributed by Minimos. See How to fix? for Minimos:latest relevant fixed versions and status.

A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade.

More details: https://vercel.com/changelog/cve-2025-48985-input-validation-bypass-on-ai-sdk

CVSS Base Scores

version 3.1