Local Code Execution Vulnerability in Firefox and Thunderbird by Mozilla
CVE-2025-4089
5.1MEDIUM
What is CVE-2025-4089?
A vulnerability exists in Mozilla's Firefox and Thunderbird, wherein insufficient escaping of special characters in the 'copy as cURL' feature may allow attackers to manipulate users into executing crafted commands. This exploitation could lead to local code execution on the affected systems, posing significant security risks to users who may unwittingly run harmful scripts.
Affected Version(s)
Firefox < 138
Thunderbird < 138
References
CVSS V3.1
Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ameen Basha M K