CVE-2025-8030
8.1Mozilla · Firefox, Thunderbird
A vulnerability in the Copy as cURL feature of Mozilla Firefox and Thunderbird allows attackers to trick users into executing arbitrary code via insufficient input escaping.
Executive summary
Mozilla Firefox and Thunderbird users are at risk of arbitrary code execution due to an input escaping flaw in the Copy as cURL feature.
Vulnerability
This vulnerability involves insufficient character escaping within the Copy as cURL functionality. The flaw allows an attacker to craft malicious input that, when copied and executed by a user, results in the execution of unexpected commands on the host system.
Business impact
A successful exploitation of this vulnerability could lead to unauthorized code execution on a user's workstation, potentially resulting in data exfiltration, system compromise, or the installation of persistent malware. With a CVSS score of 8.1, the vulnerability is classified as High severity, reflecting the significant potential for impact despite the requirement for user interaction.
Remediation
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 141 or the specified ESR releases (128.13 or 140.1) immediately to patch the vulnerable function.
Proactive Monitoring: Monitor endpoint logs for suspicious command-line activity or unauthorized process spawning that originates from terminal sessions or shell execution.
Compensating Controls: Advise users to exercise caution when copying and pasting commands from untrusted web sources into terminal environments.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high severity of this flaw and the prevalence of these applications in enterprise environments, organizations must prioritize the deployment of the latest updates. Patching the affected software is the only definitive way to eliminate the vulnerability, as it remediates the underlying code defect in the Copy as cURL feature.
More Mozilla CVEs
Sources
Originally found and disclosed by Ameen Basha M K, per the CVE Program record.