← Back

CVE-2025-5264

nvd nist
Published: May 27, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Exploitability: 1.3 / Impact: 3.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

Affected (3)

Products: Mozilla: Firefox
1 product
Firefox
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Before 139.0
Before 115.24.0
From 116.0 to 128.11.0

References (8)

Source: security@mozilla.org
Permissions Required
Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.