CVE-2025-1087

Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to arbitrary JavaScript execution in the context of the application.
CVSS

No CVSS.

References
Configurations

No configuration.

History

12 May 2025, 17:32

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-09 12:15

Updated : 2025-05-12 17:32


NVD link : CVE-2025-1087

Mitre link : CVE-2025-1087

CVE.ORG link : CVE-2025-1087


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-94

Improper Control of Generation of Code ('Code Injection')