CVE-2018-5134: Infoleak
Last updated 25 August 2025
Other sources
WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache", bypassing restrictions that only allow WebExtensions to view specific content. This vulnerability affects Firefox < 59.
— Launchpad
WebExtensions may use view-source: URLs to view local file: URL content, as well as content stored in about:cache, bypassing restrictions that only allow WebExtensions to view specific content.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-5134?
CVE-2018-5134 is a vulnerability that allows WebExtensions to view local "file:" URL content and content stored in "about:cache" in Firefox versions before 59.
How does CVE-2018-5134 impact Firefox?
CVE-2018-5134 allows WebExtensions to bypass content viewing restrictions in Firefox before version 59.
What is the severity level of CVE-2018-5134?
CVE-2018-5134 has a severity level of 7.5 (High).
How can I fix CVE-2018-5134?
To fix CVE-2018-5134, upgrade your Firefox browser to version 59 or later.
Where can I find more information about CVE-2018-5134?
More information about CVE-2018-5134 can be found on the Mozilla Bugzilla, Mozilla Security Advisories, and SecurityFocus websites.