We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.
Reserved 2025-07-22 | Published 2025-07-22 | Updated 2025-07-22 | Assigner mozillajavascript: URLs executed on object and embed tags
Mirko Brodesser
bugzilla.mozilla.org/show_bug.cgi?id=1928021
www.mozilla.org/security/advisories/mfsa2025-56/
www.mozilla.org/security/advisories/mfsa2025-58/
www.mozilla.org/security/advisories/mfsa2025-59/
www.mozilla.org/security/advisories/mfsa2025-61/
www.mozilla.org/security/advisories/mfsa2025-62/
www.mozilla.org/security/advisories/mfsa2025-63/
Support options