PT-2025-26732 · Mozilla+5 · Firefox+5
Ameen Basha M K
·
Published
2025-06-24
·
Updated
2026-02-02
·
CVE-2025-6435
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Firefox versions prior to 140
Description:
The issue arises when a user saves a response from the Network tab in Devtools using the Save As context menu option. In this scenario, the saved file may not have the
.download file extension, potentially leading to the user inadvertently running a malicious executable.Recommendations:
For versions prior to 140, update to version 140 or later to resolve the issue. As a temporary workaround, consider verifying the file extension of saved files from the Network tab in Devtools to avoid running malicious executables.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Firefox
Linuxmint
Suse
Ubuntu