Insufficient Escaping in Mozilla Firefox and Thunderbird Users
CVE-2025-11713
Currently unrated
Key Information:
- Vendor
Mozilla
- Vendor
- CVE Published:
- 14 October 2025
What is CVE-2025-11713?
A vulnerability in the 'Copy as cURL' feature of Mozilla Firefox and Thunderbird allows an attacker to exploit insufficient escaping mechanisms. This could result in misleading users into executing unintended code on Windows platforms, potentially compromising their systems. The flaw is specifically present in versions of Firefox prior to 144 and Thunderbird below 144, along with their ESR counterparts, thereby necessitating immediate action from users to mitigate risks associated with this security gap.
Affected Version(s)
Firefox < 144
Firefox ESR < 140.4
Thunderbird < 144