CVE-2025-3859

MEDIUM

Mozilla Firefox Focus < 138.0 - Open Redirect

Title source: rule
STIX 2.1

Description

Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage. This vulnerability was fixed in Focus 138.

Scores

CVSS v3 6.1
EPSS 0.0016
EPSS Percentile 36.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-451 CWE-601
Status published
Products (2)
mozilla/firefox_focus < 138.0
Mozilla/Focus 138
Published Apr 30, 2025
Tracked Since Feb 18, 2026