CVE-2025-4089Command Injection in Mozilla Firefox

Severity
5.1MEDIUMNVD
EPSS
0.1%
top 79.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 29
Latest updateFeb 2

Description

Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 138 and Thunderbird 138.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 2.5 | Impact: 2.5

Affected Packages3 packages

NVDmozilla/firefox< 138.0
NVDmozilla/thunderbird< 138.0
Ubuntumozilla/thunderbird< 1:140.7.1+build1-0ubuntu0.22.04.1

🔴Vulnerability Details

3
OSV
CVE-2025-4089: Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially2025-04-29
GHSA
GHSA-f4pj-f2qw-57cr: Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially2025-04-29
CVEList
Potential local code execution in "copy as cURL" command2025-04-29

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2026-02-02
Red Hat
firefox: thunderbird: Potential local code execution in "copy as cURL" command2025-04-29
Debian
CVE-2025-4089: firefox - Due to insufficient escaping of special characters in the "copy as cURL" feature...2025
Mozilla
Mozilla Foundation Security Advisory 2025-28: CVE-2025-4089
Mozilla
Mozilla Foundation Security Advisory 2025-31: CVE-2025-4089
CVE-2025-4089 — Command Injection in Mozilla Firefox | cvebase