MFSA-RESERVE-2025-1949994: Medium severity firefox esr vulnerability
Due to insufficient escaping of the ampersand character in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system.This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.
Other sources
Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system.This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of MFSA-RESERVE-2025-1949994?
MFSA-RESERVE-2025-1949994 has a high severity due to the potential for local code execution on affected systems.
How do I fix MFSA-RESERVE-2025-1949994?
To fix MFSA-RESERVE-2025-1949994, update Firefox ESR or Thunderbird ESR to versions 128.10 or later.
Which platforms are affected by MFSA-RESERVE-2025-1949994?
MFSA-RESERVE-2025-1949994 specifically affects Firefox running on Windows.
What feature is exploited in MFSA-RESERVE-2025-1949994?
The vulnerability in MFSA-RESERVE-2025-1949994 exploits the 'copy as cURL' feature due to insufficient escaping.
Is my version of Firefox safe from MFSA-RESERVE-2025-1949994?
Versions of Firefox other than the affected 128.10 and earlier are not vulnerable to MFSA-RESERVE-2025-1949994.