A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability was fixed in Thunderbird 128.11.1 and Thunderbird 139.0.2.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | Jul 4, 2025 | Jun 11, 2025 |
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Jun 25, 2025 | Jun 11, 2025 |
| Debian | — | Upgrade thunderbird | Jun 12, 2025 | Jun 12, 2025 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 139.0.2 | Jun 11, 2025 | Jun 10, 2025 |
| Oracle_linux | — | Upgrade thunderbird | Jul 3, 2025 | Jun 10, 2025 |
| Redhat_linux | — | Upgrade thunderbird-debuginfoNo solution existsUpgrade thunderbirdUpgrade thunderbird-debugsource | Jul 3, 2025 | Jun 11, 2025 |
| Rocky_linux | — | Upgrade thunderbird-debuginfoUpgrade thunderbirdUpgrade thunderbird-debugsource | Feb 5, 2026 | Jul 29, 2025 |
| Suse | — | Upgrade mozillathunderbird-translations-otherUpgrade mozillathunderbird-translations-commonUpgrade mozillathunderbird | Jun 30, 2025 | Jun 11, 2025 |
| Ubuntu | — | Upgrade thunderbird | Jul 22, 2025 | Jun 11, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub