Cross-Site Scripting Vulnerability in Firefox Web Browser
CVE-2025-6430

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
24 June 2025

What is CVE-2025-6430?

A vulnerability has been identified in the Firefox web browser where the Content-Disposition header is disregarded when a file is embedded using an <embed> or <object> tag. This flaw could enable attackers to execute cross-site scripting attacks, compromising user data and web application integrity. Users of affected versions should take immediate steps to update their browsers to ensure protection against potential exploitation.

Affected Version(s)

Firefox < 140

Firefox ESR < 128.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniil Satyaev (Positive Technologies)
.
CVE-2025-6430 : Cross-Site Scripting Vulnerability in Firefox Web Browser