CVE-2025-6430 — Cross-site Scripting in Mozilla Firefox
Severity
6.1MEDIUMNVD
EPSS
0.1%
top 72.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 24
Latest updateJul 22
Description
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a ` ` or ` ` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages2 packages
🔴Vulnerability Details
3GHSA▶
GHSA-fvqv-c5hj-jcrp: When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a ` ` or ` ` tag,↗2025-06-26
OSV▶
CVE-2025-6430: When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a ` ` or ` ` tag,↗2025-06-24
CVEList
▶