• Alerts
  • Events
  • DCR
    • Explore Cyware Products
    Alerts Events DCR
    Go to listing page

    Sleepless Strings - Template Injection in Insomnia

    • Malware and Vulnerabilities
    • June 23, 2025
    • tantosec
    A critical vulnerability (CVE-2025-1087) in the Insomnia API Client enables arbitrary code execution via Client-Side Template Injection (CSTI). The flaw, rated CVSS 9.3, stems from unsafe handling of untrusted input by the Nunjucks templating engine.
    Read More
    • CVE-2025-1087
    • Insomnia API Client
    Cyware Publisher

    Publisher

    Previous

    Surge in XSS Cyberattacks Targets Popular Webmail Platf ...

    Threat Actors

    Next

    BitoPro exchange links Lazarus hackers to $11 million c ...

    Breaches and Incidents


    RESOURCES
    Cyber Fusion Center Guide
    EVENTS

    News and Updates, Hacker News

    Get in touch with us now!

    1-855-692-9927


    Download Cyware Social App

    Terms of Use Privacy Policy © 2023