CVE-2025-5265
27.05.2025, 13:15
Due to insufficient escaping of the ampersand character in the Copy as cURL feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
| Vendor | Product | Version |
|---|---|---|
| mozilla | firefox | 𝑥 < 115.24.0 |
| mozilla | firefox | 𝑥 < 139.0 |
| mozilla | firefox | 116.0 ≤ 𝑥 < 128.11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| firefox |
| ||||||||||||||||
| firefox-esr |
| ||||||||||||||||
| thunderbird |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| mozjs52 |
| ||||||||||||
| firefox |
| ||||||||||||
| thunderbird |
| ||||||||||||
| mozjs38 |
| ||||||||||||
| mozjs68 |
| ||||||||||||
| mozjs78 |
| ||||||||||||
| mozjs91 |
| ||||||||||||
| mozjs102 |
| ||||||||||||
| mozjs115 |
|
References