FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Firefox -- content injection attack

Affected packages
firefox < 139.0,2

Details

VuXML ID a3291f81-3d7c-11f0-9a55-b42e991fc52e
Discovery 2025-05-27
Entry 2025-05-30

security@mozilla.org reports:

Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks.

References

CVE Name CVE-2025-5271
URL https://nvd.nist.gov/vuln/detail/CVE-2025-5271