Beveiligingsadvies

CVE-2025-1087

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-05-09 11:37:49
Laatst bijgewerkt 2025-09-17 13:48:50
Toegewezen door Kong
CVSS-score 9.3
Status PUBLISHED

Beschrijving

Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to arbitrary JavaScript execution in the context of the application.