CVE-2025-11713: Potential user-assisted code execution in “Copy as cURL” command
Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect Firefox running on other operating systems.
Other sources
Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11713?
CVE-2025-11713 is categorized as a moderate severity vulnerability due to its potential for user exploitation through the 'Copy as cURL' feature.
How do I fix CVE-2025-11713?
To mitigate CVE-2025-11713, update to the latest version of Mozilla Thunderbird or Firefox that addresses this vulnerability.
Which versions are affected by CVE-2025-11713?
CVE-2025-11713 affects Mozilla Thunderbird and Firefox versions up to 140.4 and 144 respectively.
Is CVE-2025-11713 platform-specific?
Yes, CVE-2025-11713 specifically affects Mozilla products on Windows and does not impact Firefox running on other operating systems.
What exploitation methods are associated with CVE-2025-11713?
CVE-2025-11713 could be exploited by tricking a user into executing unexpected code via an insufficiently escaped 'Copy as cURL' feature.