Insufficient Escaping in Mozilla Firefox and Thunderbird Users
CVE-2025-11713

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
14 October 2025

What is CVE-2025-11713?

A vulnerability in the 'Copy as cURL' feature of Mozilla Firefox and Thunderbird allows an attacker to exploit insufficient escaping mechanisms. This could result in misleading users into executing unintended code on Windows platforms, potentially compromising their systems. The flaw is specifically present in versions of Firefox prior to 144 and Thunderbird below 144, along with their ESR counterparts, thereby necessitating immediate action from users to mitigate risks associated with this security gap.

Affected Version(s)

Firefox < 144

Firefox ESR < 140.4

Thunderbird < 144

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hafiizh
.
CVE-2025-11713 : Insufficient Escaping in Mozilla Firefox and Thunderbird Users