CVE-2025-1087
Severity CVSS v4.0:
CRITICAL
Type:
CWE-20
Input Validation
Publication date:
09/05/2025
Last modified:
12/05/2025
Description
Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to arbitrary JavaScript execution in the context of the application.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL