firefox: thunderbird: Potential local code execution in “Copy as cURL” command

cve CVE-2025-5264 2 sources, 2 claims · Watch

Red Hat writes:
firefox: thunderbird: Potential local code execution in “Copy as cURL” command the claim

What it is to other things

affectsmozilla/firefox
NVD
made_bymozilla
NVD

What each source says

PropertySourceSaidMeans here
Cvss
cvss
conflict
NVD4.8
receipt
Source
NVD
Its words
4.8
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "115.*",
                "status": "unaffected",
                "version": "115.24",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.11",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "139",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.11",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "139",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "062A22E3-C6FE-4948-98F5-217EFE0638FC",
                "versionEndExcluding": "115.24.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
                "matchCriteriaId": "E2C0FE7C-6F8E-4F1D-A768-914194586E0C",
                "versionEndExcluding": "139.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "DA9173F0-1559-4152-9B7F-30ABCF70BE80",
                "versionEndExcluding": "128.11.0",
                "versionStartIncluding": "116.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11."
      },
      {
        "lang": "es",
        "value": "Debido a la insuficiente capacidad de escape del carácter de nueva línea en la función “Copiar como cURL”, un atacante podría engañar a un usuario para que use este comando, lo que podría provocar la ejecución de código local en su sistema. Esta vulnerabilidad afecta a Firefox < 139, Firefox ESR < 115.24 y Firefox ESR < 128.11."
      }
    ],
    "id": "CVE-2025-5264",
    "lastModified": "2026-09-30T18:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.3,
          "impactScore": 3.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-5264",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-05-28T03:55:59.370030Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-05-27T13:15:22.200",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Permissions Required"
        ],
        "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1950001"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-42/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-43/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-44/"
      },
      {
        "source": "security@mozilla.org",
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-45/"
      },
      {
        "source": "security@mozilla.org",
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-46/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00043.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00046.html"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-77"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss
cvss
conflict
Red Hat6.1
receipt
Source
Red Hat
Its words
6.1
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-5264",
  "CWE": "CWE-116",
  "advisories": [
    "RHSA-2025:9072",
    "RHSA-2025:9071",
    "RHSA-2025:9074",
    "RHSA-2025:8293",
    "RHSA-2025:9073",
    "RHSA-2025:9076",
    "RHSA-2025:9075",
    "RHSA-2025:8341",
    "RHSA-2025:9155",
    "RHSA-2025:9077",
    "RHSA-2025:8631",
    "RHSA-2025:8598",
    "RHSA-2025:8642",
    "RHSA-2025:8630",
    "RHSA-2025:8599",
    "RHSA-2025:8756",
    "RHSA-2025:8628",
    "RHSA-2025:8308",
    "RHSA-2025:8608",
    "RHSA-2025:8629",
    "RHSA-2025:8607"
  ],
  "affected_packages": [
    "firefox-0:128.11.0-1.el8_6",
    "thunderbird-0:128.11.0-1.el8_10",
    "thunderbird-0:128.11.0-1.el8_8",
    "firefox-0:128.11.0-1.el9_6",
    "firefox-0:128.11.0-1.el7_9",
    "firefox-0:128.11.0-1.el8_8",
    "thunderbird-0:128.11.0-1.el9_6",
    "thunderbird-0:128.11.0-1.el8_6",
    "firefox-0:128.11.0-1.el8_2",
    "firefox-0:128.11.0-1.el9_2",
    "firefox-0:128.11.0-1.el8_4",
    "firefox-0:128.11.0-1.el9_4",
    "firefox-0:128.11.0-1.el10_0",
    "thunderbird-0:128.11.0-1.el10_0",
    "thunderbird-0:128.11.0-1.el9_0",
    "firefox-0:128.11.0-1.el8_10",
    "firefox-0:128.11.0-1.el9_0",
    "thunderbird-0:128.11.0-1.el9_4",
    "thunderbird-0:128.11.0-1.el8_4",
    "thunderbird-0:128.11.0-1.el9_2",
    "thunderbird-0:128.11.0-1.el8_2"
  ],
  "bugzilla": "2368751",
  "bugzilla_description": "firefox: thunderbird: Potential local code execution in “Copy as cURL” command",
  "cvss3_score": "6.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-05-27T12:29:23Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-5264.json",
  "severity": "moderate"
}
—
Cwe
cwe
Red HatCWE-116
receipt
Source
Red Hat
Its words
CWE-116
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-5264",
  "CWE": "CWE-116",
  "advisories": [
    "RHSA-2025:9072",
    "RHSA-2025:9071",
    "RHSA-2025:9074",
    "RHSA-2025:8293",
    "RHSA-2025:9073",
    "RHSA-2025:9076",
    "RHSA-2025:9075",
    "RHSA-2025:8341",
    "RHSA-2025:9155",
    "RHSA-2025:9077",
    "RHSA-2025:8631",
    "RHSA-2025:8598",
    "RHSA-2025:8642",
    "RHSA-2025:8630",
    "RHSA-2025:8599",
    "RHSA-2025:8756",
    "RHSA-2025:8628",
    "RHSA-2025:8308",
    "RHSA-2025:8608",
    "RHSA-2025:8629",
    "RHSA-2025:8607"
  ],
  "affected_packages": [
    "firefox-0:128.11.0-1.el8_6",
    "thunderbird-0:128.11.0-1.el8_10",
    "thunderbird-0:128.11.0-1.el8_8",
    "firefox-0:128.11.0-1.el9_6",
    "firefox-0:128.11.0-1.el7_9",
    "firefox-0:128.11.0-1.el8_8",
    "thunderbird-0:128.11.0-1.el9_6",
    "thunderbird-0:128.11.0-1.el8_6",
    "firefox-0:128.11.0-1.el8_2",
    "firefox-0:128.11.0-1.el9_2",
    "firefox-0:128.11.0-1.el8_4",
    "firefox-0:128.11.0-1.el9_4",
    "firefox-0:128.11.0-1.el10_0",
    "thunderbird-0:128.11.0-1.el10_0",
    "thunderbird-0:128.11.0-1.el9_0",
    "firefox-0:128.11.0-1.el8_10",
    "firefox-0:128.11.0-1.el9_0",
    "thunderbird-0:128.11.0-1.el9_4",
    "thunderbird-0:128.11.0-1.el8_4",
    "thunderbird-0:128.11.0-1.el9_2",
    "thunderbird-0:128.11.0-1.el8_2"
  ],
  "bugzilla": "2368751",
  "bugzilla_description": "firefox: thunderbird: Potential local code execution in “Copy as cURL” command",
  "cvss3_score": "6.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-05-27T12:29:23Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-5264.json",
  "severity": "moderate"
}
—
Packages
packages
Red Hatfirefox-0:128.11.0-1.el8_6, thunderbird-0:128.11.0-1.el8_10, thunderbird-0:128.11.0-1.el8_8, firefox-0:128.11.0-1.el9_6, firefox-0:128.11.0-1.el7_9, firefox-0:128.11.0-1.el8_8, thunderbird-0:128.11.0-1.el9_6, thunderbird-0:128.11.0-1.el8_6, firefox-0:128.11.0-1.el8_2, firefox-0:128.11.0-1.el9_2, firefox-0:128.11.0-1.el8_4, firefox-0:128.11.0-1.el9_4, firefox-0:128.11.0-1.el10_0, thunderbird-0:128.11.0-1.el10_0, thunderbird-0:128.11.0-1.el9_0, firefox-0:128.11.0-1.el8_10, firefox-0:128.11.0-1.el9_0, thunderbird-0:128.11.0-1.el9_4, thunderbird-0:128.11.0-1.el8_4, thunderbird-0:128.11.0-1.el9_2, thunderbird-0:128.11.0-1.el8_2
receipt
Source
Red Hat
Its words
firefox-0:128.11.0-1.el8_6, thunderbird-0:128.11.0-1.el8_10, thunderbird-0:128.11.0-1.el8_8, firefox-0:128.11.0-1.el9_6, firefox-0:128.11.0-1.el7_9, firefox-0:128.11.0-1.el8_8, thunderbird-0:128.11.0-1.el9_6, thunderbird-0:128.11.0-1.el8_6, firefox-0:128.11.0-1.el8_2, firefox-0:128.11.0-1.el9_2, firefox-0:128.11.0-1.el8_4, firefox-0:128.11.0-1.el9_4, firefox-0:128.11.0-1.el10_0, thunderbird-0:128.11.0-1.el10_0, thunderbird-0:128.11.0-1.el9_0, firefox-0:128.11.0-1.el8_10, firefox-0:128.11.0-1.el9_0, thunderbird-0:128.11.0-1.el9_4, thunderbird-0:128.11.0-1.el8_4, thunderbird-0:128.11.0-1.el9_2, thunderbird-0:128.11.0-1.el8_2
Read by
field:affected_packages[]
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-5264",
  "CWE": "CWE-116",
  "advisories": [
    "RHSA-2025:9072",
    "RHSA-2025:9071",
    "RHSA-2025:9074",
    "RHSA-2025:8293",
    "RHSA-2025:9073",
    "RHSA-2025:9076",
    "RHSA-2025:9075",
    "RHSA-2025:8341",
    "RHSA-2025:9155",
    "RHSA-2025:9077",
    "RHSA-2025:8631",
    "RHSA-2025:8598",
    "RHSA-2025:8642",
    "RHSA-2025:8630",
    "RHSA-2025:8599",
    "RHSA-2025:8756",
    "RHSA-2025:8628",
    "RHSA-2025:8308",
    "RHSA-2025:8608",
    "RHSA-2025:8629",
    "RHSA-2025:8607"
  ],
  "affected_packages": [
    "firefox-0:128.11.0-1.el8_6",
    "thunderbird-0:128.11.0-1.el8_10",
    "thunderbird-0:128.11.0-1.el8_8",
    "firefox-0:128.11.0-1.el9_6",
    "firefox-0:128.11.0-1.el7_9",
    "firefox-0:128.11.0-1.el8_8",
    "thunderbird-0:128.11.0-1.el9_6",
    "thunderbird-0:128.11.0-1.el8_6",
    "firefox-0:128.11.0-1.el8_2",
    "firefox-0:128.11.0-1.el9_2",
    "firefox-0:128.11.0-1.el8_4",
    "firefox-0:128.11.0-1.el9_4",
    "firefox-0:128.11.0-1.el10_0",
    "thunderbird-0:128.11.0-1.el10_0",
    "thunderbird-0:128.11.0-1.el9_0",
    "firefox-0:128.11.0-1.el8_10",
    "firefox-0:128.11.0-1.el9_0",
    "thunderbird-0:128.11.0-1.el9_4",
    "thunderbird-0:128.11.0-1.el8_4",
    "thunderbird-0:128.11.0-1.el9_2",
    "thunderbird-0:128.11.0-1.el8_2"
  ],
  "bugzilla": "2368751",
  "bugzilla_description": "firefox: thunderbird: Potential local code execution in “Copy as cURL” command",
  "cvss3_score": "6.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-05-27T12:29:23Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-5264.json",
  "severity": "moderate"
}
—
Product
product
NVDFirefox
receipt
Source
NVD
Its words
Firefox
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "115.*",
                "status": "unaffected",
                "version": "115.24",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.11",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "139",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.11",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "139",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "062A22E3-C6FE-4948-98F5-217EFE0638FC",
                "versionEndExcluding": "115.24.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
                "matchCriteriaId": "E2C0FE7C-6F8E-4F1D-A768-914194586E0C",
                "versionEndExcluding": "139.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "DA9173F0-1559-4152-9B7F-30ABCF70BE80",
                "versionEndExcluding": "128.11.0",
                "versionStartIncluding": "116.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11."
      },
      {
        "lang": "es",
        "value": "Debido a la insuficiente capacidad de escape del carácter de nueva línea en la función “Copiar como cURL”, un atacante podría engañar a un usuario para que use este comando, lo que podría provocar la ejecución de código local en su sistema. Esta vulnerabilidad afecta a Firefox < 139, Firefox ESR < 115.24 y Firefox ESR < 128.11."
      }
    ],
    "id": "CVE-2025-5264",
    "lastModified": "2026-09-30T18:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.3,
          "impactScore": 3.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-5264",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-05-28T03:55:59.370030Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-05-27T13:15:22.200",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Permissions Required"
        ],
        "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1950001"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-42/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-43/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-44/"
      },
      {
        "source": "security@mozilla.org",
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-45/"
      },
      {
        "source": "security@mozilla.org",
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-46/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00043.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00046.html"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-77"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-5264",
  "CWE": "CWE-116",
  "advisories": [
    "RHSA-2025:9072",
    "RHSA-2025:9071",
    "RHSA-2025:9074",
    "RHSA-2025:8293",
    "RHSA-2025:9073",
    "RHSA-2025:9076",
    "RHSA-2025:9075",
    "RHSA-2025:8341",
    "RHSA-2025:9155",
    "RHSA-2025:9077",
    "RHSA-2025:8631",
    "RHSA-2025:8598",
    "RHSA-2025:8642",
    "RHSA-2025:8630",
    "RHSA-2025:8599",
    "RHSA-2025:8756",
    "RHSA-2025:8628",
    "RHSA-2025:8308",
    "RHSA-2025:8608",
    "RHSA-2025:8629",
    "RHSA-2025:8607"
  ],
  "affected_packages": [
    "firefox-0:128.11.0-1.el8_6",
    "thunderbird-0:128.11.0-1.el8_10",
    "thunderbird-0:128.11.0-1.el8_8",
    "firefox-0:128.11.0-1.el9_6",
    "firefox-0:128.11.0-1.el7_9",
    "firefox-0:128.11.0-1.el8_8",
    "thunderbird-0:128.11.0-1.el9_6",
    "thunderbird-0:128.11.0-1.el8_6",
    "firefox-0:128.11.0-1.el8_2",
    "firefox-0:128.11.0-1.el9_2",
    "firefox-0:128.11.0-1.el8_4",
    "firefox-0:128.11.0-1.el9_4",
    "firefox-0:128.11.0-1.el10_0",
    "thunderbird-0:128.11.0-1.el10_0",
    "thunderbird-0:128.11.0-1.el9_0",
    "firefox-0:128.11.0-1.el8_10",
    "firefox-0:128.11.0-1.el9_0",
    "thunderbird-0:128.11.0-1.el9_4",
    "thunderbird-0:128.11.0-1.el8_4",
    "thunderbird-0:128.11.0-1.el9_2",
    "thunderbird-0:128.11.0-1.el8_2"
  ],
  "bugzilla": "2368751",
  "bugzilla_description": "firefox: thunderbird: Potential local code execution in “Copy as cURL” command",
  "cvss3_score": "6.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-05-27T12:29:23Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-5264.json",
  "severity": "moderate"
}
medium
Status
status
NVDModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "115.*",
                "status": "unaffected",
                "version": "115.24",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.11",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "139",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.11",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "139",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "062A22E3-C6FE-4948-98F5-217EFE0638FC",
                "versionEndExcluding": "115.24.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
                "matchCriteriaId": "E2C0FE7C-6F8E-4F1D-A768-914194586E0C",
                "versionEndExcluding": "139.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "DA9173F0-1559-4152-9B7F-30ABCF70BE80",
                "versionEndExcluding": "128.11.0",
                "versionStartIncluding": "116.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11."
      },
      {
        "lang": "es",
        "value": "Debido a la insuficiente capacidad de escape del carácter de nueva línea en la función “Copiar como cURL”, un atacante podría engañar a un usuario para que use este comando, lo que podría provocar la ejecución de código local en su sistema. Esta vulnerabilidad afecta a Firefox < 139, Firefox ESR < 115.24 y Firefox ESR < 128.11."
      }
    ],
    "id": "CVE-2025-5264",
    "lastModified": "2026-09-30T18:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.3,
          "impactScore": 3.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-5264",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-05-28T03:55:59.370030Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-05-27T13:15:22.200",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Permissions Required"
        ],
        "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1950001"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-42/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-43/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-44/"
      },
      {
        "source": "security@mozilla.org",
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-45/"
      },
      {
        "source": "security@mozilla.org",
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-46/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00043.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00046.html"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-77"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDMozilla
receipt
Source
NVD
Its words
Mozilla
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "115.*",
                "status": "unaffected",
                "version": "115.24",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.11",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "139",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.11",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "139",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "062A22E3-C6FE-4948-98F5-217EFE0638FC",
                "versionEndExcluding": "115.24.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
                "matchCriteriaId": "E2C0FE7C-6F8E-4F1D-A768-914194586E0C",
                "versionEndExcluding": "139.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "DA9173F0-1559-4152-9B7F-30ABCF70BE80",
                "versionEndExcluding": "128.11.0",
                "versionStartIncluding": "116.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11."
      },
      {
        "lang": "es",
        "value": "Debido a la insuficiente capacidad de escape del carácter de nueva línea en la función “Copiar como cURL”, un atacante podría engañar a un usuario para que use este comando, lo que podría provocar la ejecución de código local en su sistema. Esta vulnerabilidad afecta a Firefox < 139, Firefox ESR < 115.24 y Firefox ESR < 128.11."
      }
    ],
    "id": "CVE-2025-5264",
    "lastModified": "2026-09-30T18:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.3,
          "impactScore": 3.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-5264",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-05-28T03:55:59.370030Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-05-27T13:15:22.200",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Permissions Required"
        ],
        "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1950001"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-42/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-43/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-44/"
      },
      {
        "source": "security@mozilla.org",
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-45/"
      },
      {
        "source": "security@mozilla.org",
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-46/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00043.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00046.html"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-77"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

firefox: thunderbird: Potential local code execution in “Copy as cURL” command
zetlyn/cve-redhat · 2025-05-27
cvss 6.1 cwe CWE-116 packages firefox-0:128.11.0-1.el8_6, thunderbird-0:128.11.0-1.el8_10, thunderbird-0:128.11.0-1.el8_8, firefox-0:128.11.0-1.el9_6, firefox-0:128.11.0-1.el7_9, firefox-0:128.11.0-1.el8_8, thunderbird-0:128.11.0-1.el9_6, thunderbird-0:128.11.0-1.el8_6, firefox-0:128.11.0-1.el8_2, firefox-0:128.11.0-1.el9_2, firefox-0:128.11.0-1.el8_4, firefox-0:128.11.0-1.el9_4, firefox-0:128.11.0-1.el10_0, thunderbird-0:128.11.0-1.el10_0, thunderbird-0:128.11.0-1.el9_0, firefox-0:128.11.0-1.el8_10, firefox-0:128.11.0-1.el9_0, thunderbird-0:128.11.0-1.el9_4, thunderbird-0:128.11.0-1.el8_4, thunderbird-0:128.11.0-1.el9_2, thunderbird-0:128.11.0-1.el8_2 severity moderate source
Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.
zetlyn/cve-nvd · 2025-05-27
cvss 4.8 product Firefox status Modified vendor Mozilla source