CVE-2025-4088
MEDIUMMozilla Firefox < 138.0 - CSRF
Title source: ruleDescription
A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability affects Firefox < 138 and Thunderbird < 138.
Scores
CVSS v3
6.5
EPSS
0.0012
EPSS Percentile
30.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Classification
CWE
CWE-352
Status
published
Affected Products (2)
mozilla/firefox
< 138.0
mozilla/thunderbird
< 138.0
Timeline
Published
Apr 29, 2025
Tracked Since
Feb 18, 2026