CVE-2025-4084: Potential local code execution in "copy as cURL" command
Due to insufficient escaping of the ampersand character in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system.This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.
Other sources
Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.. This vulnerability was fixed in Firefox ESR 128.10, Firefox ESR 115.23, and Thunderbird 128.10.
— MITRE
Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system.This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4084?
The severity of CVE-2025-4084 is rated as critical due to the potential for local code execution.
How do I fix CVE-2025-4084?
To fix CVE-2025-4084, users should update to the latest version of Firefox or Firefox ESR that addresses this vulnerability.
Who is affected by CVE-2025-4084?
CVE-2025-4084 specifically affects users of Firefox for Windows versions up to 128.10 and certain versions of Firefox ESR and Thunderbird ESR.
What can an attacker achieve with CVE-2025-4084?
An attacker can exploit CVE-2025-4084 to trick users into running potentially malicious commands through the 'copy as cURL' feature.
Is CVE-2025-4084 present in versions after 128.10?
No, CVE-2025-4084 is only present in Firefox for Windows versions prior to 128.10, as the issue is resolved in subsequent updates.