PT-2025-18153 · Mozilla+2 · Firefox Esr+3

Ameen Basha M K

·

Published

2025-04-29

·

Updated

2025-10-31

·

CVE-2025-4084

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox ESR versions prior to 128.10 Firefox ESR versions prior to 115.23 Thunderbird ESR versions prior to 128.10
Description The issue arises from insufficient escaping of special characters in the "copy as cURL" feature. This could allow an attacker to trick a user into executing a command, potentially leading to local code execution on the user's system.
Recommendations For Firefox ESR versions prior to 128.10, update to version 128.10 or later. For Firefox ESR versions prior to 115.23, update to version 115.23 or later. For Thunderbird ESR versions prior to 128.10, update to version 128.10 or later.

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6254
ALT-PU-2025-7022
ALT-PU-2025-7695
BDU:2025-10509
CVE-2025-4084
DLA-4167-1
OESA-2025-1486
OESA-2025-1487
OESA-2025-1488
OESA-2025-1489
OESA-2025-2557
OPENSUSE-SU-2025:15042-1
OPENSUSE-SU-2025_1436-1
OPENSUSE-SU-2025_1506-1
SUSE-SU-2025:1436-1
SUSE-SU-2025:1506-1

Affected Products

Alt Linux
Firefox Esr
Suse
Thunderbird Esr