CVE-2025-8030

8.1

Mozilla · Firefox, Thunderbird

A vulnerability in the Copy as cURL feature of Mozilla Firefox and Thunderbird allows attackers to trick users into executing arbitrary code via insufficient input escaping.

Executive summary

Mozilla Firefox and Thunderbird users are at risk of arbitrary code execution due to an input escaping flaw in the Copy as cURL feature.

Vulnerability

This vulnerability involves insufficient character escaping within the Copy as cURL functionality. The flaw allows an attacker to craft malicious input that, when copied and executed by a user, results in the execution of unexpected commands on the host system.

Business impact

A successful exploitation of this vulnerability could lead to unauthorized code execution on a user's workstation, potentially resulting in data exfiltration, system compromise, or the installation of persistent malware. With a CVSS score of 8.1, the vulnerability is classified as High severity, reflecting the significant potential for impact despite the requirement for user interaction.

Remediation

Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 141 or the specified ESR releases (128.13 or 140.1) immediately to patch the vulnerable function.

Proactive Monitoring: Monitor endpoint logs for suspicious command-line activity or unauthorized process spawning that originates from terminal sessions or shell execution.

Compensating Controls: Advise users to exercise caution when copying and pasting commands from untrusted web sources into terminal environments.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high severity of this flaw and the prevalence of these applications in enterprise environments, organizations must prioritize the deployment of the latest updates. Patching the affected software is the only definitive way to eliminate the vulnerability, as it remediates the underlying code defect in the Copy as cURL feature.

More Mozilla CVEs

Sources

Originally found and disclosed by Ameen Basha M K, per the CVE Program record.