First published: Tue Apr 29 2025(Updated: )
Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox ESR < 128.10, Firefox ESR < 115.23, and Thunderbird ESR < 128.10.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <128.10 | |
Firefox ESR | <128.10<115.23 | |
Mozilla Thunderbird | <128.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-4084 is rated as critical due to the potential for local code execution.
To fix CVE-2025-4084, users should update to the latest version of Firefox or Firefox ESR that addresses this vulnerability.
CVE-2025-4084 specifically affects users of Firefox for Windows versions up to 128.10 and certain versions of Firefox ESR and Thunderbird ESR.
An attacker can exploit CVE-2025-4084 to trick users into running potentially malicious commands through the 'copy as cURL' feature.
No, CVE-2025-4084 is only present in Firefox for Windows versions prior to 128.10, as the issue is resolved in subsequent updates.