Potential local code execution in “Copy as cURL” command
Summary
| CVE | CVE-2025-5264 |
|---|---|
| State | PUBLISHED |
| Assigner | mozilla |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-05-27 13:15:22 UTC |
| Updated | 2026-04-13 15:17:03 UTC |
| Description | Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11. |
Risk And Classification
Primary CVSS: v3.1 4.8 MEDIUM from ADP
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Problem Types: CWE-77 | CWE-77 CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 4.8 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 4.8 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
RequiredScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
LowCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Mozilla | Firefox | unaffected 115.24 115.* rpm | Not specified |
| CNA | Mozilla | Firefox | unaffected 128.11 128.* rpm | Not specified |
| CNA | Mozilla | Firefox | unaffected 139 * rpm | Not specified |
| CNA | Mozilla | Thunderbird | unaffected 128.11 128.* rpm | Not specified |
| CNA | Mozilla | Thunderbird | unaffected 139 * rpm | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| lists.debian.org/debian-lts-announce/2025/05/msg00043.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | |
| lists.debian.org/debian-lts-announce/2025/05/msg00046.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | |
| www.mozilla.org/security/advisories/mfsa2025-42 | [email protected] | www.mozilla.org | Vendor Advisory |
| www.mozilla.org/security/advisories/mfsa2025-43 | [email protected] | www.mozilla.org | Vendor Advisory |
| www.mozilla.org/security/advisories/mfsa2025-45 | [email protected] | www.mozilla.org | |
| www.mozilla.org/security/advisories/mfsa2025-44 | [email protected] | www.mozilla.org | Vendor Advisory |
| www.mozilla.org/security/advisories/mfsa2025-46 | [email protected] | www.mozilla.org | |
| bugzilla.mozilla.org/show_bug.cgi | [email protected] | bugzilla.mozilla.org | Permissions Required |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Ameen Basha M K (en)
There are currently no legacy QID mappings associated with this CVE.