CVE-2025-13017: Same-origin policy bypass in the DOM: Notifications component
Same-origin policy bypass in the DOM: Notifications component. This vulnerability affects Firefox < 145 and Firefox ESR < 140.5.
Other sources
Same-origin policy bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
— MITRE
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-13017?
CVE-2025-13017 is classified as a high-severity vulnerability due to its potential impact on the security of user notifications.
How do I fix CVE-2025-13017?
To fix CVE-2025-13017, users should update to Firefox version 145 or later, or Firefox ESR version 140.5 or later.
What are the affected versions for CVE-2025-13017?
CVE-2025-13017 affects Firefox versions earlier than 145 and Firefox ESR versions earlier than 140.5.
Can CVE-2025-13017 impact my web applications?
Yes, CVE-2025-13017 can allow attackers to bypass the same-origin policy, potentially compromising web applications.
Is CVE-2025-13017 being actively exploited?
As of now, there is no public information indicating that CVE-2025-13017 is being actively exploited in the wild.