When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.
CVSS Details
- CVSS 3.1 Base Score: 6.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-thunderbird | Apr 29, 2025 | Apr 15, 2025 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-thunderbirdamazon-linux-ami-2-upgrade-thunderbird-debuginfo | May 30, 2025 | Apr 15, 2025 | |
| Debian | debian-upgrade-thunderbird | May 5, 2025 | Apr 15, 2025 | |
| Mozilla Thunderbird | mozilla-thunderbird-upgrade-128_9_2 | Apr 16, 2025 | Apr 15, 2025 | |
| Oracle_linux | — | oracle-linux-upgrade-thunderbird | Apr 29, 2025 | Apr 15, 2025 |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-thunderbirdredhat-upgrade-thunderbird-debuginforedhat-upgrade-thunderbird-debugsource | Apr 29, 2025 | Apr 15, 2025 | |
| Rocky_linux | rocky-upgrade-thunderbirdrocky-upgrade-thunderbird-debuginforocky-upgrade-thunderbird-debugsource | Jul 31, 2025 | Jul 29, 2025 | |
| Suse | — | suse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-other | Apr 25, 2025 | Apr 15, 2025 |
| Ubuntu | ubuntu-upgrade-thunderbird | Jul 23, 2025 | Apr 15, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub