Home
CRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:H/SI:H/SA:LDefault status
unaffected
Any version
affected
Description
Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to arbitrary JavaScript execution in the context of the application.
Problem types
CWE-20 Improper Input Validation
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
Any version
References
tantosec.com/...5/06/insomnia-api-client-template-injection/