CVE-2025-13019: Same-origin policy bypass in the DOM: Workers component
Same-origin policy bypass in the DOM: Workers component. This vulnerability affects Firefox < 145 and Firefox ESR < 140.5.
Other sources
Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
— MITRE
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-13019?
CVE-2025-13019 has been classified as a high severity vulnerability due to its potential to allow a same-origin policy bypass.
How do I fix CVE-2025-13019?
To mitigate CVE-2025-13019, users should update to Firefox version 145 or later and Firefox ESR version 140.5 or later.
Which versions of Firefox are affected by CVE-2025-13019?
CVE-2025-13019 affects Firefox versions prior to 145 and Firefox ESR versions prior to 140.5.
What type of vulnerability is CVE-2025-13019?
CVE-2025-13019 is a same-origin policy bypass vulnerability affecting the DOM: Workers component.
What should I do if I cannot update Firefox due to compatibility issues related to CVE-2025-13019?
If updating Firefox is not an option, consider switching to a different browser that is not affected by CVE-2025-13019.