PT-2025-25209 · Mozilla+10 · Thunderbird+10

Dario Weißer

·

Published

2025-06-10

·

Updated

2025-10-01

·

CVE-2025-5986

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 128.11.1 Thunderbird versions prior to 139.0.2
Description A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content.
Recommendations For Thunderbird versions prior to 128.11.1, update to version 128.11.1 or later to resolve the issue. For Thunderbird versions prior to 139.0.2, update to version 139.0.2 or later to resolve the issue. As a temporary workaround, consider disabling HTML mode for email viewing until a patch is available. Restrict access to external content when viewing emails in HTML mode to minimize the risk of exploitation.

Fix

UI Misrepresentation of Critical Information

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:10195
ALSA-2025:10196
ALSA-2025:10246
ALT-PU-2025-11495
ALT-PU-2025-8611
BDU:2025-08579
CESA-2025_10246
CVE-2025-5986
DLA-4239-1
DSA-5959-1
INFSA-2025_10196
INFSA-2025_10246
MGASA-2025-0197
OESA-2025-1835
OPENSUSE-SU-2025:15204-1
RHSA-2025:10159
RHSA-2025:10160
RHSA-2025:10161
RHSA-2025:10163
RHSA-2025:10164
RHSA-2025:10165
RHSA-2025:10166
RHSA-2025:10195
RHSA-2025:10196
RHSA-2025:10246
RHSA-2025_10196
RHSA-2025_10246
SUSE-SU-2025:02158-1
USN-7663-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Thunderbird
Ubuntu