FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Mozilla -- insufficient character escaping

Affected packages
firefox < 138.0,2
thunderbird < 138.0

Details

VuXML ID a59bd59e-2e85-11f0-a989-b42e991fc52e
Discovery 2025-04-29
Entry 2025-05-11

security@mozilla.org reports:

Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system.

References

CVE Name CVE-2025-4089
URL https://nvd.nist.gov/vuln/detail/CVE-2025-4089