CVE-2025-5264: Potential local code execution in “Copy as cURL” command
Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-5264?
CVE-2025-5264 is considered a critical vulnerability due to its potential for local code execution.
How do I fix CVE-2025-5264?
To fix CVE-2025-5264, update Mozilla Firefox to version 139 or Firefox ESR to version 115.24 or 128.11.
What systems are affected by CVE-2025-5264?
CVE-2025-5264 affects Mozilla Firefox versions prior to 139 and Firefox ESR versions prior to 115.24 and 128.11.
What type of vulnerability is CVE-2025-5264?
CVE-2025-5264 is a command injection vulnerability due to insufficient escaping of newline characters.
Can CVE-2025-5264 lead to remote attacks?
CVE-2025-5264 does not directly allow remote attacks but can lead to local code execution if exploited.