CVE-2025-6427

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*

History

13 Apr 2026, 15:17

Type Values Removed Values Added
Summary (en) An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140 and Thunderbird < 140. (en) An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

14 Jul 2025, 19:15

Type Values Removed Values Added
References
  • () https://www.mozilla.org/security/advisories/mfsa2025-54/ -
Summary (en) An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140. (en) An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140 and Thunderbird < 140.

03 Jul 2025, 16:37

Type Values Removed Values Added
First Time Mozilla firefox
Mozilla
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1966927 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1966927 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-51/ - () https://www.mozilla.org/security/advisories/mfsa2025-51/ - Vendor Advisory

25 Jun 2025, 15:15

Type Values Removed Values Added
CWE CWE-693
Summary
  • (es) Un atacante logró eludir la directiva `connect-src` de una Política de Seguridad de Contenido manipulando subdocumentos. Esto también habría ocultado las conexiones de la pestaña Red en DevTools. Esta vulnerabilidad afecta a Firefox anterior a la versión 140.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

24 Jun 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-24 13:15

Updated : 2026-04-13 15:17


NVD link : CVE-2025-6427

Mitre link : CVE-2025-6427

CVE.ORG link : CVE-2025-6427


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-693

Protection Mechanism Failure