CVE-2025-13013: Mitigation bypass in the DOM: Core & HTML component
Mitigation bypass in the DOM: Core & HTML component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, and Firefox ESR < 115.30.
Other sources
Mitigation bypass in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.
— MITRE
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-13013?
CVE-2025-13013 has been classified with a moderate severity level due to its potential for a mitigation bypass.
How do I fix CVE-2025-13013?
To mitigate CVE-2025-13013, upgrade to Firefox version 145 or higher, or Firefox ESR version 140.5 or higher.
Which versions of Firefox are affected by CVE-2025-13013?
CVE-2025-13013 affects Firefox versions prior to 145, as well as Firefox ESR versions prior to 140.5 and 115.30.
Is CVE-2025-13013 specific to a certain platform?
CVE-2025-13013 is specific to Firefox and Firefox ESR on all supported platforms.
Can CVE-2025-13013 lead to any user data exposure?
While CVE-2025-13013 specifically concerns a mitigation bypass, there is potential for exploitation that could lead to user data exposure.