Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system.
*This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Jun 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11. | Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11. |
References |
|
Thu, 05 Jun 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mozilla
Mozilla firefox |
|
CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* |
|
Vendors & Products |
Mozilla
Mozilla firefox |
Thu, 29 May 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | firefox: Potential local code execution in “Copy as cURL” command | firefox: thunderbird: Potential local code execution in “Copy as cURL” command |
Wed, 28 May 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | firefox: Potential local code execution in “Copy as cURL” command | |
Weaknesses | CWE-116 | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 27 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-77 | |
Metrics |
cvssV3_1
|
Tue, 27 May 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11. | |
References |
|

Status: PUBLISHED
Assigner: mozilla
Published: 2025-05-27T12:29:24.338Z
Updated: 2025-06-11T12:07:47.307Z
Reserved: 2025-05-27T12:29:23.953Z
Link: CVE-2025-5265

Updated: 2025-05-27T15:10:05.453Z

Status : Modified
Published: 2025-05-27T13:15:22.303
Modified: 2025-06-11T12:15:27.553
Link: CVE-2025-5265
