cbcvebase.
CVE-2025-3859
published 2025-04-30

CVE-2025-3859: Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into…

PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.17%
6.8th percentile
Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage. This vulnerability was fixed in Focus 138.

Affected

2 ranges
VendorProductVersion rangeFixed in
mozillafirefox
mozillafirefox_focus< 138.0138.0

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.