Local Code Execution Vulnerability in Firefox for Windows
CVE-2025-5265

4.8MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
27 May 2025

What is CVE-2025-5265?

A security flaw has been identified in the 'Copy as cURL' feature of Firefox for Windows, where the ampersand character is insufficiently escaped. This may allow an attacker to manipulate a user into executing a crafted command, leading to potential local code execution on the user's system. This issue primarily affects specific versions of Firefox and Firefox ESR, which could expose users to unauthorized access and execution of commands.

Affected Version(s)

Firefox < 139

Firefox ESR < 115.24

Firefox ESR < 128.11

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ameen Basha M K
.
CVE-2025-5265 : Local Code Execution Vulnerability in Firefox for Windows