Insufficient Escaping in Firefox and Thunderbird Products by Mozilla
CVE-2025-8030

8.1HIGH

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
22 July 2025

What is CVE-2025-8030?

A vulnerability exists in Mozilla's Firefox and Thunderbird products that arises from insufficient escaping in the 'Copy as cURL' functionality. This flaw could potentially allow attackers to craft malicious commands that trick users into executing unintended code. Affected versions include Firefox versions prior to 141, Firefox ESR prior to 128.13 and 140.1, and Thunderbird versions prior to 141, 128.13, and 140.1. It is crucial for users to update their applications to prevent exploitation of this vulnerability.

Affected Version(s)

Firefox < 141

Firefox ESR < 128.13

Firefox ESR < 140.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ameen Basha M K
.
CVE-2025-8030 : Insufficient Escaping in Firefox and Thunderbird Products by Mozilla