CVE-2025-3859

Severity
6.1MEDIUM
EPSS
0.2%
top 63.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 30

Description

Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage This vulnerability affects Focus < 138.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5mozilla/focusunspecified138

🔴Vulnerability Details

2
CVEList
CVE-2025-3859: Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick us2025-04-30
GHSA
GHSA-4jh7-c2vv-7qf2: Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick us2025-04-30

📋Vendor Advisories

1
Mozilla
Mozilla Foundation Security Advisory 2025-33: CVE-2025-3859
CVE-2025-3859 (MEDIUM CVSS 6.1) | Websites directing users to long UR | cvebase.io