Description
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.
Product status
140 (rpm)
140 (rpm)
Credits
Daniil Satyaev (Positive Technologies)
References
lists.debian.org/debian-lts-announce/2025/07/msg00002.html
lists.debian.org/debian-lts-announce/2025/06/msg00029.html
bugzilla.mozilla.org/show_bug.cgi?id=1971140
www.mozilla.org/security/advisories/mfsa2025-51/
www.mozilla.org/security/advisories/mfsa2025-53/
www.mozilla.org/security/advisories/mfsa2025-54/
www.mozilla.org/security/advisories/mfsa2025-55/