First published: Tue Apr 29 2025(Updated: )
Due to insufficient escaping of the ampersand character in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system.This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox ESR | <128.10 | 128.10 |
Mozilla Thunderbird | <128.10 | 128.10 |
Firefox ESR | <115.23 | 115.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
MFSA-RESERVE-2025-1949994 has a high severity due to the potential for local code execution on affected systems.
To fix MFSA-RESERVE-2025-1949994, update Firefox ESR or Thunderbird ESR to versions 128.10 or later.
MFSA-RESERVE-2025-1949994 specifically affects Firefox running on Windows.
The vulnerability in MFSA-RESERVE-2025-1949994 exploits the 'copy as cURL' feature due to insufficient escaping.
Versions of Firefox other than the affected 128.10 and earlier are not vulnerable to MFSA-RESERVE-2025-1949994.