CVE-2025-5986
published 2025-06-11CVE-2025-5986: A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.47%
37.4th percentile
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability was fixed in Thunderbird 128.11.1 and Thunderbird 139.0.2.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:128.12.0esr-1~deb12u1 (bookworm) | thunderbird 1:128.12.0esr-1~deb12u1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 128.11.1 | 128.11.1 |
| mozilla | thunderbird | >= 0 < 1:128.12.0esr-1~deb11u1 | 1:128.12.0esr-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:128.12.0esr-1~deb12u1 | 1:128.12.0esr-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:128.12.0esr-1 | 1:128.12.0esr-1 |
| mozilla | thunderbird | >= 0 < 1:128.12.0esr-1 | 1:128.12.0esr-1 |
| mozilla | thunderbird | >= 135.0 < 139.0.2 | 139.0.2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-5986: A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of
osv·2025-06-11·CVSS 6.5
CVE-2025-5986 [MEDIUM] CVE-2025-5986: A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability affects Thunderbird < 128.11.1 and Thunderbird < 139.0.2.
GHSA
GHSA-q7fj-77gc-45xq: A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of
ghsa_unreviewed·2025-06-11
CVE-2025-5986 [MEDIUM] CWE-451 GHSA-q7fj-77gc-45xq: A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability affects Thunderbird < 128.11.1 and Thunderbird < 139.0.2.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2025-07-22
CVE-2025-4083 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart thunderbird to
make all the necessary changes.
Red Hat
thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links
vendor_redhat·2025-06-10·CVSS 6.5
CVE-2025-5986 [MEDIUM] CWE-400 thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links
thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability affects Thunderbird < 128.11.1 and Thunderbird < 139.0.2.
A flaw was found in Thunderbird. The Mozilla Foundati
Debian
CVE-2025-5986: thunderbird - A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited ...
vendor_debian·2025·CVSS 6.5
CVE-2025-5986 [MEDIUM] CVE-2025-5986: thunderbird - A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited ...
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability affects Thunderbird < 128.11.1 and Thunderbird < 139.0.2.
Scope: local
bookworm: resolved (fixed in 1:128.12.0esr-1~deb12u1)
bullseye: resolved (fixed in 1:128.12.0esr-1~deb11u1)
forky: resolved (fixed in 1:128.12.0esr-1)
Mozilla
Mozilla Foundation Security Advisory 2025-49: CVE-2025-5986
vendor_mozilla·CVSS 6.5
CVE-2025-5986 [MEDIUM] Mozilla Foundation Security Advisory 2025-49: CVE-2025-5986
Mozilla Foundation Security Advisory 2025-49
CVE: CVE-2025-5986
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 128.11.1
Mozilla
Mozilla Foundation Security Advisory 2025-35: CVE-2025-5986
vendor_mozilla·CVSS 6.5
CVE-2025-5986 [MEDIUM] Mozilla Foundation Security Advisory 2025-35: CVE-2025-5986
Mozilla Foundation Security Advisory 2025-35
CVE: CVE-2025-5986
Product: Thunderbird
Impact: low
Fixed in: Thunderbird 138.0.1
Mozilla
Mozilla Foundation Security Advisory 2025-50: CVE-2025-5986
vendor_mozilla·CVSS 6.5
CVE-2025-5986 [MEDIUM] Mozilla Foundation Security Advisory 2025-50: CVE-2025-5986
Mozilla Foundation Security Advisory 2025-50
CVE: CVE-2025-5986
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 139.0.2
Mozilla
Mozilla Foundation Security Advisory 2025-34: CVE-2025-5986
vendor_mozilla·CVSS 6.5
CVE-2025-5986 [MEDIUM] Mozilla Foundation Security Advisory 2025-34: CVE-2025-5986
Mozilla Foundation Security Advisory 2025-34
CVE: CVE-2025-5986
Product: Thunderbird
Impact: low
Fixed in: Thunderbird 128.10.1
No detection rules found.
No public exploits indexed.
2025-06-11
Published