CVE-2018-18497: Medium severity Mozilla Firefox vulnerability
Last updated 25 August 2025
Other sources
Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.
— Launchpad
Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to opened privileged about: or file: locations.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-18497?
CVE-2018-18497 is a vulnerability that allows a malicious WebExtension in Mozilla Firefox to open privileged about: or file: locations.
How can I exploit CVE-2018-18497?
You can exploit CVE-2018-18497 by using a pipe in the URL field of a WebExtension to load multiple pages as a single argument.
Which software is affected by CVE-2018-18497?
Mozilla Firefox versions up to 64.0 and Ubuntu with Firefox package versions up to 64.0 are affected by CVE-2018-18497.
What is the severity of CVE-2018-18497?
CVE-2018-18497 has a severity rating of 6.5 (medium).
Where can I find more information about CVE-2018-18497?
You can find more information about CVE-2018-18497 at the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1488180), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2018-29/), [SecurityFocus](http://www.securityfocus.com/bid/106167).