A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability was fixed in Thunderbird 128.11.1 and Thunderbird 139.0.2.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-thunderbird | Jul 4, 2025 | Jun 11, 2025 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-thunderbirdamazon-linux-ami-2-upgrade-thunderbird-debuginfo | Jun 25, 2025 | Jun 11, 2025 | |
| Debian | debian-upgrade-thunderbird | Jun 12, 2025 | Jun 12, 2025 | |
| Mozilla Thunderbird | mozilla-thunderbird-upgrade-139_0_2 | Jun 11, 2025 | Jun 10, 2025 | |
| Oracle_linux | — | oracle-linux-upgrade-thunderbird | Jul 3, 2025 | Jun 10, 2025 |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-thunderbirdredhat-upgrade-thunderbird-debuginforedhat-upgrade-thunderbird-debugsource | Jul 3, 2025 | Jun 11, 2025 | |
| Rocky_linux | rocky-upgrade-thunderbirdrocky-upgrade-thunderbird-debuginforocky-upgrade-thunderbird-debugsource | Feb 5, 2026 | Jul 29, 2025 | |
| Suse | — | suse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-other | Jun 30, 2025 | Jun 11, 2025 |
| Ubuntu | ubuntu-upgrade-thunderbird | Jul 22, 2025 | Jun 11, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub