Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 138 and Thunderbird < 138.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-77 | |
Metrics |
cvssV3_1
|
Tue, 29 Apr 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 138 and Thunderbird < 138. | |
References |
|

Status: PUBLISHED
Assigner: mozilla
Published: 2025-04-29T13:13:45.152Z
Updated: 2025-04-30T03:56:31.921Z
Reserved: 2025-04-29T13:13:44.377Z
Link: CVE-2025-4089

Updated: 2025-04-29T15:38:41.023Z

Status : Received
Published: 2025-04-29T14:15:35.537
Modified: 2025-04-29T16:15:39.297
Link: CVE-2025-4089

No data.