CVE-2025-6429

MEDIUM

Firefox <140-ESR<128.12 - CSRF

Title source: llm
STIX 2.1

Description

Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

Scores

CVSS v3 6.5
EPSS 0.0043
EPSS Percentile 62.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-116
Status published
Products (6)
mozilla/firefox < 128.12.0
mozilla/firefox < 140.0
Mozilla/Firefox 128.12 - 128.*
Mozilla/Firefox 140
Mozilla/Thunderbird 128.12 - 128.*
Mozilla/Thunderbird 140
Published Jun 24, 2025
Tracked Since Feb 18, 2026