CVE-2025-13018: Mitigation bypass in the DOM: Security component
Mitigation bypass in the DOM: Security component. This vulnerability affects Firefox < 145 and Firefox ESR < 140.5.
Other sources
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
— MITRE
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-13018?
CVE-2025-13018 is considered a moderate severity vulnerability affecting the DOM security component in Firefox.
How do I fix CVE-2025-13018?
To mitigate CVE-2025-13018, update to Firefox version 145 or newer, or Firefox ESR version 140.5 or newer.
Which versions of Firefox are affected by CVE-2025-13018?
CVE-2025-13018 affects Firefox versions prior to 145 and Firefox ESR versions prior to 140.5.
What type of vulnerability is CVE-2025-13018?
CVE-2025-13018 is a mitigation bypass vulnerability found in the security component of the DOM.
Is there a workaround for CVE-2025-13018?
There are no known workarounds for CVE-2025-13018, so updating is the recommended action.