Impact
An attacker who can send HTML chat messages through Matrix or XMPP can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. The injected content can alter the appearance of the chat window and provide misleading or malicious links to end‑users, potentially leading to credential theft or other social engineering attacks. This vulnerability does not enable code execution or privileged escalation, but it can directly influence user behavior through the interface.
Affected Systems
Mozilla Thunderbird clients up to 152.0.0 and 140.12.0 are affected. This is inferred from the fix release numbers, as the advisory records the issue being resolved in 152.0.1 and 140.12.1. Therefore any release before those fixes lacks the protection and is considered vulnerable.
Risk and Exploitability
The CVSS score of 6.5 classifies this vulnerability as Medium severity, with an EPSS score of < 1% and no listing in the CISA KEV catalog. Exploitation requires only that an attacker be able to send a message via Matrix or XMPP to the victim; it does not enable remote code execution or require elevated privileges. Because the payload is rendered in the user interface, the risk is primarily phishing links and UI manipulation that can deceive users into clicking malicious content.
OpenCVE Enrichment
Debian DLA
Debian DSA