CVE-2025-8030: Potential user-assisted code execution in “Copy as cURL” command
Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 128.13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 141 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 141 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 128.13 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 141 - Upgrade
Upgrade
Thunderbird ESRto a version that resolves this vulnerability.Fixed in 128.13 - Upgrade
Upgrade
Thunderbird ESRto a version that resolves this vulnerability.Fixed in 140.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-8030?
The severity of CVE-2025-8030 is considered moderate due to its potential for misuse in code execution.
How do I fix CVE-2025-8030?
To fix CVE-2025-8030, update to the latest version of Mozilla Firefox or Firefox ESR that addresses this vulnerability.
What features are impacted by CVE-2025-8030?
CVE-2025-8030 affects the 'Copy as cURL' feature in Mozilla Firefox which may allow unexpected code execution.
Which versions of Mozilla Firefox are affected by CVE-2025-8030?
CVE-2025-8030 affects Mozilla Firefox versions up to 141 and Firefox ESR versions up to 128.13 and 140.1.
Can CVE-2025-8030 be exploited remotely?
CVE-2025-8030 could be exploited remotely if a user is tricked into executing malicious cURL commands.