CVE-2025-5264

MEDIUM

Firefox < 115.24.0, 115.24-115.*, 128.11-128.*, >=139 - Command Injection via Copy as cURL Feature

Title source: llm
STIX 2.1

Description

Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

Scores

CVSS v3 4.8
EPSS 0.0013
EPSS Percentile 32.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (7)
mozilla/firefox < 115.24.0
mozilla/firefox < 139.0
Mozilla/Firefox 115.24 - 115.*
Mozilla/Firefox 128.11 - 128.*
Mozilla/Firefox 139
Mozilla/Thunderbird 128.11 - 128.*
Mozilla/Thunderbird 139
Published May 27, 2025
Tracked Since Feb 18, 2026