Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.
CVSS Details
- CVSS 3.1 Base Score: 4.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade firefoxUpgrade thunderbird-debuginfoUpgrade thunderbirdUpgrade firefox-debuginfo | Jun 12, 2025 | May 27, 2025 |
| Amazon_linux_2023 | — | Upgrade firefox-debuginfoUpgrade firefoxUpgrade firefox-debugsource | Jun 11, 2025 | May 27, 2025 |
| Mfsa2025 42 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 139.0 | May 28, 2025 | May 27, 2025 |
| Mfsa2025 43 | — | Upgrade to Mozilla Firefox ESR version 115.24Upgrade to the latest version of Mozilla Firefox | May 28, 2025 | May 27, 2025 |
| Mfsa2025 44 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 128.11 | May 28, 2025 | May 27, 2025 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 128.11 | May 28, 2025 | May 27, 2025 |
| Suse | — | Upgrade MozillaThunderbird-translations-otherUpgrade libmozjs-128-0Upgrade mozjs128-develUpgrade MozillaFirefoxUpgrade MozillaThunderbirdUpgrade MozillaFirefox-translations-commonUpgrade mozillafirefox-branding-upstreamUpgrade MozillaThunderbird-translations-commonUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-develUpgrade mozjs128 | Jun 3, 2025 | May 27, 2025 |
| Ubuntu | — | Upgrade thunderbird | Jun 26, 2025 | May 27, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub