Description
Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect Firefox running on other operating systems. This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
Problem types
Potential user-assisted code execution in “Copy as cURL” command
Product status
Credits
Hafiizh
References
bugzilla.mozilla.org/show_bug.cgi?id=1986142
www.mozilla.org/security/advisories/mfsa2025-81/
www.mozilla.org/security/advisories/mfsa2025-83/
www.mozilla.org/security/advisories/mfsa2025-84/
www.mozilla.org/security/advisories/mfsa2025-85/