CVE-2025-1087 CRITICAL

CVE-2025-1087: Arbitrary Code Execution in Kong Insomnia Desktop Application

Vendor Kong Inc.
Product Insomnia
Weakness CWE-20 · Input validation
Published May 9, 2025
Last update September 17, 2025

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L

What the vulnerability does

01Description

Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to arbitrary JavaScript execution in the context of the application.

Key dates

02Disclosure timeline

May 9, 2025 CVE published
September 17, 2025 Record updated