CVE-2025-5264

Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*

History

13 Apr 2026, 15:17

Type Values Removed Values Added
Summary (en) Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11. (en) Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

03 Nov 2025, 20:19

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/05/msg00043.html -
  • () https://lists.debian.org/debian-lts-announce/2025/05/msg00046.html -

11 Jun 2025, 12:15

Type Values Removed Values Added
Summary (en) Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11. (en) Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
References
  • () https://www.mozilla.org/security/advisories/mfsa2025-45/ -
  • () https://www.mozilla.org/security/advisories/mfsa2025-46/ -

04 Jun 2025, 20:13

Type Values Removed Values Added
First Time Mozilla firefox
Mozilla
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1950001 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1950001 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-42/ - () https://www.mozilla.org/security/advisories/mfsa2025-42/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-43/ - () https://www.mozilla.org/security/advisories/mfsa2025-43/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-44/ - () https://www.mozilla.org/security/advisories/mfsa2025-44/ - Vendor Advisory

28 May 2025, 15:01

Type Values Removed Values Added
Summary
  • (es) Debido a la insuficiente capacidad de escape del carácter de nueva línea en la función "Copiar como cURL", un atacante podría engañar a un usuario para que use este comando, lo que podría provocar la ejecución de código local en su sistema. Esta vulnerabilidad afecta a Firefox &lt; 139, Firefox ESR &lt; 115.24 y Firefox ESR &lt; 128.11.

27 May 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
CWE CWE-77

27 May 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-27 13:15

Updated : 2026-04-13 15:17


NVD link : CVE-2025-5264

Mitre link : CVE-2025-5264

CVE.ORG link : CVE-2025-5264


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')