CVE-2018-5176: Input Validation
Last updated 25 August 2025
Other sources
The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If a JSON file contains malicious JavaScript script embedded as "javascript:" links, users may be tricked into clicking and running this code in the context of the JSON Viewer. This can allow for the theft of cookies and authorization tokens which are accessible to that context. This vulnerability affects Firefox < 60.
— Launchpad
The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including javascript: links. If a JSON file contains malicious JavaScript script embedded as javascript: links, users may be tricked into clicking and running this code in the context of the JSON Viewer. This can allow for the theft of cookies and authorization tokens which are accessible to that context.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5159
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5168
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5174
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
- CVE-2018-5150
Frequently Asked Questions
What is CVE-2018-5176?
CVE-2018-5176 is a vulnerability in the JSON Viewer of Mozilla Firefox that allows for the execution of malicious JavaScript code through clickable hyperlinks.
How does CVE-2018-5176 work?
CVE-2018-5176 works by displaying clickable hyperlinks for URLs in a JSON file, including 'javascript:' links, which can trick users into executing malicious code.
Which software is affected by CVE-2018-5176?
Mozilla Firefox versions up to and exclusive of 60.0, as well as Ubuntu with Firefox versions up to and exclusive of 60.0, are affected by CVE-2018-5176.
What is the severity of CVE-2018-5176?
CVE-2018-5176 has a severity value of 6.1, indicating a medium severity level.
How can I fix CVE-2018-5176?
To fix CVE-2018-5176, update your Mozilla Firefox or Ubuntu with Firefox to a version higher than 60.0.