Local Code Execution Vulnerability in Firefox and Thunderbird by Mozilla
CVE-2025-4089
5.1MEDIUM
What is CVE-2025-4089?
A vulnerability exists in Mozilla's Firefox and Thunderbird, wherein insufficient escaping of special characters in the 'copy as cURL' feature may allow attackers to manipulate users into executing crafted commands. This exploitation could lead to local code execution on the affected systems, posing significant security risks to users who may unwittingly run harmful scripts.
Affected Version(s)
Firefox < 138
Thunderbird < 138