CVE-2025-4089

CVSS 3.1 Score 5.1 of 10 (medium)

Details

Published Apr 29, 2025
Updated: May 9, 2025
CWE ID 77

Summary

CVE-2025-4089 is a vulnerability affecting Firefox versions below 138 and Thunderbird versions below 138. The flaw lies in the "copy as cURL" feature, which fails to properly escape special characters. An attacker could manipulate this vulnerability to deceive users into executing malicious commands, potentially resulting in local code execution on their systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mozilla Firefox
  • Mozilla Thunderbird

Affected Vendors

  • Mozilla