CVE-2025-1087 Details
Description
Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to arbitrary JavaScript execution in the context of the application.
A template injection vulnerability has been identified in the Kong Insomnia Desktop Application, affecting versions prior to 11.0.2. This vulnerability allows attackers to execute arbitrary code by exploiting insufficient validation of user-supplied input in template strings, leading to unauthorized execution of JavaScript within the application.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 9, 2025CISA-ADP
Assessed May 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Kong/insomnia | Kong | ProductSource CodeVendor |
| https://tantosec.com/blog/2025/06/insomnia-api-client-template-injection/ | CVE |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | Kong |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | Kong |
Affected Products
| Product | Versions |
|---|---|
| Kong Insomnia | < 11.0.2 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Kong |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 17, 2025 | CVE Modified | CVE |
| May 9, 2025 | New CVE Received | Kong |
Volerion