When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.
CVSS Details
- CVSS 3.1 Base Score: 6.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | Apr 29, 2025 | Apr 15, 2025 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade thunderbird-debuginfo | May 30, 2025 | Apr 15, 2025 |
| Debian | — | Upgrade thunderbird | May 5, 2025 | Apr 15, 2025 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 128.9.2 | Apr 16, 2025 | Apr 15, 2025 |
| Oracle_linux | — | Upgrade thunderbird | Apr 29, 2025 | Apr 15, 2025 |
| Redhat_linux | — | Upgrade thunderbirdUpgrade thunderbird-debuginfoNo solution existsUpgrade thunderbird-debugsource | Apr 29, 2025 | Apr 15, 2025 |
| Rocky_linux | — | Upgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceUpgrade thunderbird | Jul 31, 2025 | Jul 29, 2025 |
| Suse | — | Upgrade mozillathunderbirdUpgrade mozillathunderbird-translations-otherUpgrade mozillathunderbird-translations-common | Apr 25, 2025 | Apr 15, 2025 |
| Ubuntu | — | Upgrade thunderbird | Jul 23, 2025 | Apr 15, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub