PT-2025-41901 · Mozilla+4 · Thunderbird+6

Published

2025-10-14

·

Updated

2026-04-15

·

CVE-2025-11713

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 144 Firefox ESR versions prior to 140.4 Thunderbird versions prior to 144 Thunderbird versions prior to 140.4
Description A flaw exists in the “Copy as cURL” feature due to insufficient escaping. This could allow an attacker to trick a user into executing unexpected code on Windows systems. The issue does not affect Firefox running on operating systems other than Windows.
Recommendations Update Firefox to version 144 or later. Update Firefox ESR to version 140.4 or later. Update Thunderbird to version 144 or later. Update Thunderbird to version 140.4 or later.

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-13161
ALT-PU-2025-13476
ALT-PU-2025-13478
ALT-PU-2025-13988
ALT-PU-2025-14599
BDU:2025-13293
CVE-2025-11713
MGASA-2025-0246
MGASA-2025-0247
OPENSUSE-SU-2025:15632-1
OPENSUSE-SU-2025:15645-1
OPENSUSE-SU-2025:15646-1
OPENSUSE-SU-2025:20026-1
OPENSUSE-SU-2025:20065-1
SUSE-SU-2025:21021-1
SUSE-SU-2025:3775-1
SUSE-SU-2025:3808-1
SUSE-SU-2025:4006-1
SUSE-SU-2025:4173-1
SUSE-SU-2025:4174-1
USN-7991-1

Affected Products

Alt Linux
Firefox
Firefox Esr
Linuxmint
Suse
Thunderbird
Ubuntu