CVE-2025-8030Code Injection in Mozilla Firefox

CWE-94Code Injection13 documents8 sources
Severity
8.1HIGHNVD
EPSS
0.1%
top 80.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 22
Latest updateFeb 2

Description

Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages3 packages

NVDmozilla/firefox140.0140.1.0+2
NVDmozilla/thunderbird140.0140.1.0+2
Debianmozilla/thunderbird< 1:128.13.0esr-1~deb11u1+3

🔴Vulnerability Details

3
CVEList
Potential user-assisted code execution in “Copy as cURL” command2025-07-22
GHSA
GHSA-3q2p-xj33-xm8j: Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code2025-07-22
OSV
CVE-2025-8030: Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code2025-07-22

📋Vendor Advisories

9
Ubuntu
Thunderbird vulnerabilities2026-02-02
Red Hat
firefox: thunderbird: Potential user-assisted code execution in “Copy as cURL” command2025-07-22
Debian
CVE-2025-8030: firefox - Insufficient escaping in the “Copy as cURL” feature could potentially be used to...2025
Mozilla
Mozilla Foundation Security Advisory 2025-59: CVE-2025-8030
Mozilla
Mozilla Foundation Security Advisory 2025-58: CVE-2025-8030
CVE-2025-8030 — Code Injection in Mozilla Firefox | cvebase