cbcvebase.
CVE-2025-4089
published 2025-04-29

CVE-2025-4089: Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading…

medium5.1CVSS 3.1
AVLACLPRNUINSUCLILAN
Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 138 and Thunderbird 138.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianfirefox< firefox 138.0-1 (sid)firefox 138.0-1 (sid)
mozillafirefox< 138.0138.0
mozillafirefox
mozillathunderbird< 138.0138.0
mozillathunderbird>= 0 < 1:140.7.1+build1-0ubuntu0.22.04.11:140.7.1+build1-0ubuntu0.22.04.1

CVSS provenance

nvdv3.15.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv5.1MEDIUM