First published: Fri May 09 2025(Updated: )
Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to arbitrary JavaScript execution in the context of the application.
Credit: 02762ae7-200e-4b20-9b2b-a77d5b8fc4cb
Affected Software | Affected Version | How to fix |
---|---|---|
Kong Insomnia | <11.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1087 is classified as a high severity vulnerability due to its ability to execute arbitrary code.
To fix CVE-2025-1087, update the Kong Insomnia Desktop Application to version 11.0.2 or later.
CVE-2025-1087 affects all versions of the Kong Insomnia Desktop Application prior to 11.0.2.
CVE-2025-1087 is caused by insufficient validation of user-supplied input when processing template strings.
Yes, CVE-2025-1087 can allow attackers to execute arbitrary code remotely if exploited.