Local Code Execution Vulnerability in Firefox and Thunderbird by Mozilla
CVE-2025-4089

5.1MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
29 April 2025

What is CVE-2025-4089?

A vulnerability exists in Mozilla's Firefox and Thunderbird, wherein insufficient escaping of special characters in the 'copy as cURL' feature may allow attackers to manipulate users into executing crafted commands. This exploitation could lead to local code execution on the affected systems, posing significant security risks to users who may unwittingly run harmful scripts.

Affected Version(s)

Firefox < 138

Thunderbird < 138

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ameen Basha M K
.
CVE-2025-4089 : Local Code Execution Vulnerability in Firefox and Thunderbird by Mozilla