CVE-2019-17016: XSS
Last updated 25 August 2025
Other sources
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
— Launchpad
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2020-02/#CVE-2019-17016
— Red Hat
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-17016.
What is the title of this vulnerability?
The title of this vulnerability is 'When pasting a <style> tag from the clipboard into a rich text editor the CSS sanitizer incorrectly rewrites a @namespace rule.'
What is the severity of CVE-2019-17016?
The severity of CVE-2019-17016 is high (7).
Which software products are affected by CVE-2019-17016?
The software products affected by CVE-2019-17016 are Mozilla Firefox ESR 68.4, Mozilla Firefox 72, and Mozilla Thunderbird 68.4.1.
How can this vulnerability be exploited?
This vulnerability can be exploited by pasting a <style> tag from the clipboard into a rich text editor.