Local Code Execution Vulnerability in Firefox for Windows
CVE-2025-5265
4.8MEDIUM
What is CVE-2025-5265?
A security flaw has been identified in the 'Copy as cURL' feature of Firefox for Windows, where the ampersand character is insufficiently escaped. This may allow an attacker to manipulate a user into executing a crafted command, leading to potential local code execution on the user's system. This issue primarily affects specific versions of Firefox and Firefox ESR, which could expose users to unauthorized access and execution of commands.
Affected Version(s)
Firefox < 139
Firefox ESR < 115.24
Firefox ESR < 128.11