Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system.
*This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox ESR < 128.10, Firefox ESR < 115.23, and Thunderbird ESR < 128.10.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Apr 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox ESR < 128.10, Firefox ESR < 115.23, and Thunderbird ESR < 128.10. | |
References |
|

Status: PUBLISHED
Assigner: mozilla
Published: 2025-04-29T13:13:38.073Z
Updated: 2025-04-30T03:56:29.231Z
Reserved: 2025-04-29T13:13:37.330Z
Link: CVE-2025-4084

No data.

Status : Received
Published: 2025-04-29T14:15:35.097
Modified: 2025-04-29T14:15:35.097
Link: CVE-2025-4084

No data.