diff --git a/package-lock.json b/package-lock.json
index c3584a036a..f0227bae21 100644
--- a/package-lock.json
+++ b/package-lock.json
@@ -11325,9 +11325,9 @@
"license": "MIT"
},
"node_modules/@xmldom/xmldom": {
- "version": "0.8.12",
- "resolved": "https://registry.npmjs.org/@xmldom/xmldom/-/xmldom-0.8.12.tgz",
- "integrity": "sha512-9k/gHF6n/pAi/9tqr3m3aqkuiNosYTurLLUtc7xQ9sxB/wm7WPygCv8GYa6mS0fLJEHhqMC1ATYhz++U/lRHqg==",
+ "version": "0.8.13",
+ "resolved": "https://registry.npmjs.org/@xmldom/xmldom/-/xmldom-0.8.13.tgz",
+ "integrity": "sha512-KRYzxepc14G/CEpEGc3Yn+JKaAeT63smlDr+vjB8jRfgTBBI9wRj/nkQEO+ucV8p8I9bfKLWp37uHgFrbntPvw==",
"license": "MIT",
"engines": {
"node": ">=10.0.0"
@@ -29938,9 +29938,9 @@
}
},
"packages/insomnia/node_modules/@xmldom/xmldom": {
- "version": "0.9.9",
- "resolved": "https://registry.npmjs.org/@xmldom/xmldom/-/xmldom-0.9.9.tgz",
- "integrity": "sha512-qycIHAucxy/LXAYIjmLmtQ8q9GPnMbnjG1KXhWm9o5sCr6pOYDATkMPiTNa6/v8eELyqOQ2FsEqeoFYmgv/gJg==",
+ "version": "0.9.10",
+ "resolved": "https://registry.npmjs.org/@xmldom/xmldom/-/xmldom-0.9.10.tgz",
+ "integrity": "sha512-A9gOqLdi6cV4ibazAjcQufGj0B1y/vDqYrcuP6d/6x8P27gRS8643Dj9o1dEKtB6O7fwxb2FgBmJS2mX7gpvdw==",
"license": "MIT",
"engines": {
"node": ">=14.6"
diff --git a/packages/insomnia-component-docs/package-lock.json b/packages/insomnia-component-docs/package-lock.json
index da16019540..436290e9cc 100644
--- a/packages/insomnia-component-docs/package-lock.json
+++ b/packages/insomnia-component-docs/package-lock.json
@@ -26,7 +26,7 @@
"typescript": "~5.6.2"
},
"engines": {
- "node": ">=22.0"
+ "node": ">=24.0"
}
},
"node_modules/@ai-sdk/gateway": {
@@ -9144,9 +9144,10 @@
"license": "ISC"
},
"node_modules/glob": {
- "version": "10.4.5",
- "resolved": "https://registry.npmjs.org/glob/-/glob-10.4.5.tgz",
- "integrity": "sha512-7Bv8RF0k6xjo7d4A/PxYLbUCfb6c+Vpd2/mB2yRDlew7Jb5hEXiCD9ibfO7wpk8i4sevK6DFny9h7EYbM3/sHg==",
+ "version": "10.5.0",
+ "resolved": "https://registry.npmjs.org/glob/-/glob-10.5.0.tgz",
+ "integrity": "sha512-DfXN8DfhJ7NH3Oe7cFmu3NCu1wKbkReJ8TorzSAFbSKrlNaQSKfIzqYqVY8zlbs2NLBbWpRiU52GX2PbaBVNkg==",
+ "deprecated": "Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me",
"license": "ISC",
"dependencies": {
"foreground-child": "^3.1.0",
diff --git a/packages/insomnia/src/common/render.ts b/packages/insomnia/src/common/render.ts
index cfcbcccfac..d401b3f349 100644
--- a/packages/insomnia/src/common/render.ts
+++ b/packages/insomnia/src/common/render.ts
@@ -129,6 +129,9 @@ export async function buildRenderContext({
const keys = _getOrderedEnvironmentKeys(subObject);
for (const key of keys) {
+ if (key === '__proto__' || key === 'constructor' || key === 'prototype') {
+ continue;
+ }
/*
* If we're overwriting a string, try to render it first using the same key from the base
* environment to support same-variable recursion. This allows for the following scenario:
diff --git a/packages/insomnia/src/ui/components/.client/codemirror/extensions/autocomplete.ts b/packages/insomnia/src/ui/components/.client/codemirror/extensions/autocomplete.ts
index 5732d6b08a..799357adfb 100644
--- a/packages/insomnia/src/ui/components/.client/codemirror/extensions/autocomplete.ts
+++ b/packages/insomnia/src/ui/components/.client/codemirror/extensions/autocomplete.ts
@@ -529,7 +529,9 @@ function escapeHTML(unsafeText: string) {
function renderHintMatch(li: HTMLElement, _allHints: CodeMirror.Hints, hint: Hint) {
// Bold the matched text
const { displayText, segment, type, displayValue } = hint;
- const markedName = replaceWithSurround(displayText || '', segment, '', '');
+ const escapedDisplayText = escapeHTML(displayText || '');
+ const escapedSegment = escapeHTML(segment);
+ const markedName = replaceWithSurround(escapedDisplayText, escapedSegment, '', '');
const { char, title } = ICONS[type];
let safeValue = '';
diff --git a/packages/insomnia/src/ui/components/.client/codemirror/extensions/nunjucks-tags.ts b/packages/insomnia/src/ui/components/.client/codemirror/extensions/nunjucks-tags.ts
index d86d165d38..2f1e3e9e6e 100644
--- a/packages/insomnia/src/ui/components/.client/codemirror/extensions/nunjucks-tags.ts
+++ b/packages/insomnia/src/ui/components/.client/codemirror/extensions/nunjucks-tags.ts
@@ -137,7 +137,7 @@ async function _highlightNunjucksTags(
el.setAttribute('draggable', 'true');
el.dataset.error = 'off';
el.dataset.template = tok.string;
- el.innerHTML = '' + tok.string;
+ el.replaceChildren(document.createElement('label'), document.createTextNode(tok.string));
const mark = this.markText(start, end, {
// @ts-expect-error not a known property of TextMarkerOptions
__nunjucks: true,
@@ -295,7 +295,7 @@ async function _updateElementText(
// @ts-expect-error -- TSCONVERSION
const foundOption = firstArg.options.find(d => d.value === argData.value);
const option = foundOption || firstArg.options[0];
- innerHTML = `${tagDefinition.displayName} ⇒ ${option.displayName}`;
+ innerHTML = `${tagDefinition.displayName} ⇒ ${option.displayName}`;
} else {
innerHTML = tagDefinition.displayName || tagData.name;
}
@@ -333,9 +333,13 @@ async function _updateElementText(
if (dataError === 'on') {
el.dataset.error = dataError;
- el.innerHTML = '' + cleanedStr;
+ const label = document.createElement('label');
+ const icon = document.createElement('i');
+ icon.className = 'fa fa-exclamation-triangle';
+ label.append(icon);
+ el.replaceChildren(label, document.createTextNode(cleanedStr));
} else {
- el.innerHTML = '' + innerHTML;
+ el.replaceChildren(document.createElement('label'), document.createTextNode(innerHTML));
}
mark.changed();
diff --git a/packages/insomnia/src/ui/components/base/highlight.tsx b/packages/insomnia/src/ui/components/base/highlight.tsx
deleted file mode 100644
index a7fafd73ab..0000000000
--- a/packages/insomnia/src/ui/components/base/highlight.tsx
+++ /dev/null
@@ -1,37 +0,0 @@
-import fuzzySort from 'fuzzysort';
-import React, { type FC } from 'react';
-
-import { fuzzyMatch } from '../../../common/misc';
-
-export interface HighlightProps {
- search: string;
- text: string;
- blankValue?: string;
-}
-
-export const Highlight: FC = ({ search, text, blankValue, ...otherProps }) => {
- // Match loose here to make sure our highlighting always works
- const result = fuzzyMatch(search, text, {
- splitSpace: true,
- loose: true,
- });
-
- if (!result) {
- return {text || blankValue || ''};
- }
-
- return (
- ',
- '',
- ),
- }}
- />
- );
-};