CVE-2023-40299 describes a critical vulnerability in Kong Insomnia 2023.4.0 on macOS, allowing attackers to execute arbitrary code, access restricted files, or trigger TCC permission requests. This local vulnerability, rated 7.8 HIGH, requires user interaction and leverages the DYLD_INSERT_LIBRARIES environment variable for exploitation, leading to high impacts on confidentiality, integrity, and availability. While the vulnerability is severe, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2023.4.0CPE matchmatch criteria | cpe:2.3:a:konghq:insomnia:2023.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.