Description
Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.
Published: 2025-05-27
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Code Execution
Action: Patch
AI Analysis

Impact

The flaw in the “Copy as cURL” feature arises from inadequate handling of newline characters, allowing an attacker to embed malicious command fragments into the generated cURL string. When a user mistakenly executes the copied command, the embedded code can run with the user’s privileges, resulting in local code execution. This vulnerability combines unescaped input and command‑injection issues, classified under CWE‑116 and CWE‑77.

Affected Systems

The vulnerability affects Mozilla Firefox versions prior to 139, including Firefox ESR 115.24 and ESR 128.11, as well as Thunderbird versions prior to 139 and Thunderbird ESR 128.11.

Risk and Exploitability

The CVSS score of 4.8 indicates medium impact when the flaw is used. The EPSS score of less than 1% shows a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction, typically through a social engineering scenario where a malicious site or email tempts the victim to run the copied command. The attack vector is local, leveraging the user’s own system. Consequently, while the impact can be severe, the likelihood of real‑world attacks is currently low.

Generated by OpenCVE AI on April 20, 2026 at 20:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 139 or later, or to Firefox ESR 115.24/128.11, and upgrade Thunderbird to version 139 or later or to Thunderbird ESR 128.11; this applies the official patch that removes the newline escape flaw.
  • If an upgrade cannot be performed immediately, disable or avoid using the "Copy as cURL" command until the patch is installed; this eliminates the vulnerable entry point.
  • Monitor for phishing or malicious sites that offer automated cURL commands and implement user training and web‑filtering controls to reduce the chance that a user will execute a malicious copy.

Generated by OpenCVE AI on April 20, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4191-1 firefox-esr security update
Debian DLA Debian DLA DLA-4194-1 thunderbird security update
Debian DSA Debian DSA DSA-5926-1 firefox-esr security update
Debian DSA Debian DSA DSA-5932-1 thunderbird security update
EUVD EUVD EUVD-2025-16338 Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
Ubuntu USN Ubuntu USN USN-7663-1 Thunderbird vulnerabilities
History

Mon, 13 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11. Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

Sat, 28 Feb 2026 05:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Nov 2025 20:30:00 +0000


Thu, 30 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Title firefox: thunderbird: Potential local code execution in “Copy as cURL” command Potential local code execution in “Copy as cURL” command

Mon, 16 Jun 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Els
CPEs cpe:/o:redhat:rhel_els:7
Vendors & Products Redhat rhel Els

Wed, 11 Jun 2025 12:15:00 +0000

Type Values Removed Values Added
Description Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11. Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
References

Tue, 10 Jun 2025 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Aus
Redhat rhel Tus
CPEs cpe:/a:redhat:rhel_aus:8.2
cpe:/a:redhat:rhel_aus:8.4
cpe:/a:redhat:rhel_aus:8.6
cpe:/a:redhat:rhel_e4s:8.6
cpe:/a:redhat:rhel_e4s:8.8
cpe:/a:redhat:rhel_e4s:9.2
cpe:/a:redhat:rhel_tus:8.6
cpe:/a:redhat:rhel_tus:8.8
Vendors & Products Redhat rhel Aus
Redhat rhel Tus

Fri, 06 Jun 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel E4s
Redhat rhel Eus
CPEs cpe:/a:redhat:rhel_e4s:9.0
cpe:/a:redhat:rhel_eus:9.4
Vendors & Products Redhat rhel E4s
Redhat rhel Eus

Wed, 04 Jun 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
Vendors & Products Mozilla
Mozilla firefox

Tue, 03 Jun 2025 06:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:10.0

Thu, 29 May 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:8
cpe:/a:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux

Thu, 29 May 2025 02:45:00 +0000

Type Values Removed Values Added
Title firefox: thunderbird: Potential local code execution in “Copy as cURL” command
Weaknesses CWE-116
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 27 May 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 27 May 2025 12:45:00 +0000

Type Values Removed Values Added
Description Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.
References

Subscriptions

Mozilla Firefox
Redhat Enterprise Linux Rhel Aus Rhel E4s Rhel Els Rhel Eus Rhel Tus
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-13T14:27:58.589Z

Reserved: 2025-05-27T12:29:23.106Z

Link: CVE-2025-5264

cve-icon Vulnrichment

Updated: 2025-11-03T20:05:59.028Z

cve-icon NVD

Status : Modified

Published: 2025-05-27T13:15:22.200

Modified: 2026-04-13T15:17:03.793

Link: CVE-2025-5264

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-05-27T12:29:23Z

Links: CVE-2025-5264 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T20:45:16Z

Weaknesses