CVE-2025-1087: Arbitrary Code Execution in Kong Insomnia Desktop Application
Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to arbitrary JavaScript execution in the context of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1087?
CVE-2025-1087 is classified as a high severity vulnerability due to its ability to execute arbitrary code.
How do I fix CVE-2025-1087?
To fix CVE-2025-1087, update the Kong Insomnia Desktop Application to version 11.0.2 or later.
What versions of the Kong Insomnia Desktop Application are affected by CVE-2025-1087?
CVE-2025-1087 affects all versions of the Kong Insomnia Desktop Application prior to 11.0.2.
What causes the CVE-2025-1087 vulnerability?
CVE-2025-1087 is caused by insufficient validation of user-supplied input when processing template strings.
Can CVE-2025-1087 allow remote code execution?
Yes, CVE-2025-1087 can allow attackers to execute arbitrary code remotely if exploited.