Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.
CVSS Details
- CVSS 3.1 Base Score: 4.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-firefoxamazon-linux-ami-2-upgrade-firefox-debuginfoamazon-linux-ami-2-upgrade-thunderbirdamazon-linux-ami-2-upgrade-thunderbird-debuginfo | Jun 12, 2025 | May 27, 2025 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-firefoxamazon-linux-2023-upgrade-firefox-debuginfoamazon-linux-2023-upgrade-firefox-debugsource | Jun 11, 2025 | May 27, 2025 | |
| Mfsa2025 42 | mozilla-firefox-upgrade-139_0 | May 28, 2025 | May 27, 2025 | |
| Mfsa2025 43 | mozilla-firefox-esr-upgrade-115_24 | May 28, 2025 | May 27, 2025 | |
| Mfsa2025 44 | mozilla-firefox-esr-upgrade-128_11 | May 28, 2025 | May 27, 2025 | |
| Mozilla Thunderbird | mozilla-thunderbird-upgrade-128_11 | May 28, 2025 | May 27, 2025 | |
| Suse | — | suse-upgrade-libmozjs-128-0suse-upgrade-mozillafirefoxsuse-upgrade-mozillafirefox-branding-upstreamsuse-upgrade-mozillafirefox-develsuse-upgrade-mozillafirefox-translations-commonsuse-upgrade-mozillafirefox-translations-othersuse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-othersuse-upgrade-mozjs128suse-upgrade-mozjs128-devel | Jun 3, 2025 | May 27, 2025 |
| Ubuntu | ubuntu-upgrade-thunderbird | Jun 26, 2025 | May 27, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub