REDHAT-BUG-2366283: High severity thunderbird vulnerability

Published May 14, 2025
·
Updated

Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may incorrectly render it as HTML when opened, allowing the embedded JavaScript to run without requiring a file download. This behavior relies on Thunderbird auto-saving the attachment to /tmp and linking to it via the file:/// protocol, potentially enabling JavaScript execution as part of the HTML. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.

Affected Software

2 affected components
Mozilla Thunderbird<128.10.1
Mozilla Thunderbird<138.0.1

Event History

May 14, 2025
Data Sourced
via Red Hat·06:01 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2366283?

The severity of REDHAT-BUG-2366283 is considered high due to its potential for executing JavaScript maliciously via crafted email attachments.

2

How do I fix REDHAT-BUG-2366283?

To fix REDHAT-BUG-2366283, users should update their Mozilla Thunderbird to the latest version that addresses this vulnerability.

3

What versions of Thunderbird are affected by REDHAT-BUG-2366283?

Versions of Thunderbird up to 128.10.1 and 138.0.1 are affected by REDHAT-BUG-2366283.

4

What type of exploit is associated with REDHAT-BUG-2366283?

REDHAT-BUG-2366283 can be exploited by crafting a nested email attachment that misleads the application to render content as HTML.

5

Is there any workaround for REDHAT-BUG-2366283?

While the best solution is to update Thunderbird, users may consider disabling preview of email attachments as a temporary workaround for REDHAT-BUG-2366283.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203