CVE-2025-4089: Potential local code execution in "copy as cURL" command
Published Apr 29, 2025
·Updated
Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system.
Affected Software
6 affected componentsFixes available
Mozilla Firefox<138
Mozilla Thunderbird<138
Mozilla Thunderbird<138
138
Mozilla Firefox<138
138
Mozilla Firefox<138.0
Mozilla Thunderbird<138.0
Event History
Apr 29, 2025
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·01:13 PM
Data Sourced
via MITRE·01:13 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-4089?
The severity of CVE-2025-4089 is considered to be critical due to its potential for local code execution.
2
How do I fix CVE-2025-4089?
To fix CVE-2025-4089, update Firefox or Thunderbird to the latest version that is 138 or higher.
3
What versions of software are affected by CVE-2025-4089?
CVE-2025-4089 affects Firefox versions lower than 138 and Thunderbird versions lower than 138.
4
What is the impact of exploiting CVE-2025-4089?
Exploiting CVE-2025-4089 could allow an attacker to execute local commands on a user's system.
5
Who is at risk from CVE-2025-4089?
Users of outdated versions of Firefox and Thunderbird are at risk from CVE-2025-4089.