CVE-2025-1087

Severity CVSS v4.0:
CRITICAL
Type:
CWE-20 Input Validation
Publication date:
09/05/2025
Last modified:
12/05/2025

Description

Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to arbitrary JavaScript execution in the context of the application.

References to Advisories, Solutions, and Tools