PT-2025-26732 · Mozilla+5 · Firefox+5

Ameen Basha M K

·

Published

2025-06-24

·

Updated

2026-02-02

·

CVE-2025-6435

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Firefox versions prior to 140
Description: The issue arises when a user saves a response from the Network tab in Devtools using the Save As context menu option. In this scenario, the saved file may not have the .download file extension, potentially leading to the user inadvertently running a malicious executable.
Recommendations: For versions prior to 140, update to version 140 or later to resolve the issue. As a temporary workaround, consider verifying the file extension of saved files from the Network tab in Devtools to avoid running malicious executables.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

ALT-PU-2025-11100
ALT-PU-2025-11495
ALT-PU-2025-11497
ALT-PU-2025-14599
ALT-PU-2025-8725
ALT-PU-2025-9988
BDU:2025-08993
CVE-2025-6435
OPENSUSE-SU-2025:15325-1
OPENSUSE-SU-2025:15371-1
OPENSUSE-SU-2025:15383-1
SUSE-SU-2025:02339-1
SUSE-SU-2025:02529-1
SUSE-SU-2025:02546-1
SUSE-SU-2025_02339-1
SUSE-SU-2025_02529-1
USN-7991-1

Affected Products

Alt Linux
Astra Linux
Firefox
Linuxmint
Suse
Ubuntu