CVE-2023-23599: Malicious command could be hidden in devtools output on Windows
When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-23599?
CVE-2023-23599 is a vulnerability in Firefox, Thunderbird, and Firefox ESR that allows arbitrary commands to be hidden within network requests when copying them as curl commands.
Which software versions are affected by CVE-2023-23599?
Firefox versions earlier than 109, Thunderbird versions earlier than 102.7, and Firefox ESR versions earlier than 102.7 are affected by CVE-2023-23599.
What is the severity of CVE-2023-23599?
CVE-2023-23599 has a severity rating of 6.5, which is considered medium.
How can I fix CVE-2023-23599?
To fix CVE-2023-23599, update to Firefox version 109 or later, Thunderbird version 102.7 or later, or Firefox ESR version 102.7 or later.
Where can I find more information about CVE-2023-23599?
You can find more information about CVE-2023-23599 on the Mozilla security advisories page.