We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-1087

Arbitrary Code Execution in Kong Insomnia Desktop Application



Description

Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to arbitrary JavaScript execution in the context of the application.

Reserved 2025-02-06 | Published 2025-05-09 | Updated 2025-05-09 | Assigner Kong


CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L

Problem types

CWE-20 Improper Input Validation

CWE-94 Improper Control of Generation of Code ('Code Injection')

Product status

Default status
unaffected

Any version
affected

References

github.com/Kong/insomnia

cve.org (CVE-2025-1087)

nvd.nist.gov (CVE-2025-1087)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-1087

Support options

Helpdesk Chat, Email, Knowledgebase