File Content Disclosure Vulnerability in Mozilla Firefox
CVE-2025-1936
7.3HIGH
Summary
This vulnerability in Mozilla Firefox allows attackers to retrieve local file content from ZIP archives. By manipulating URLs with jar: protocols, it exploits how null characters and extensions are processed, enabling harmful code to be disguised as legitimate content such as images. This poses a risk, as the exploited web extensions can potentially reveal sensitive information or execute unauthorized scripts.
Affected Version(s)
Firefox < 136
Firefox ESR < 128.8
Thunderbird < 136
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Surya Dev Singh