Files
CVEs-PoC/2025/CVE-2025-1087.md
T
2025-09-29 21:09:30 +02:00

1.0 KiB

CVE-2025-1087

Description

Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to arbitrary JavaScript execution in the context of the application.

POC

Reference

Github