Description
An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.
Published: 2026-07-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker who can send HTML chat messages through Matrix or XMPP can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. The injected content can alter the appearance of the chat window and provide misleading or malicious links to end‑users, potentially leading to credential theft or other social engineering attacks. This vulnerability does not enable code execution or privileged escalation, but it can directly influence user behavior through the interface.

Affected Systems

Mozilla Thunderbird clients up to 152.0.0 and 140.12.0 are affected. This is inferred from the fix release numbers, as the advisory records the issue being resolved in 152.0.1 and 140.12.1. Therefore any release before those fixes lacks the protection and is considered vulnerable.

Risk and Exploitability

The CVSS score of 6.5 classifies this vulnerability as Medium severity, with an EPSS score of < 1% and no listing in the CISA KEV catalog. Exploitation requires only that an attacker be able to send a message via Matrix or XMPP to the victim; it does not enable remote code execution or require elevated privileges. Because the payload is rendered in the user interface, the risk is primarily phishing links and UI manipulation that can deceive users into clicking malicious content.

Generated by OpenCVE AI on August 4, 2026 at 08:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Thunderbird to version 152.0.1, 140.12.1, or any newer release that includes the fix.
  • Disable HTML rendering for Matrix and XMPP messages in the chat settings so that received messages are treated as plain text.
  • Educate users to verify links before clicking, as phishing links may be used.

Generated by OpenCVE AI on August 4, 2026 at 08:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4727-1 thunderbird security update
Debian DSA Debian DSA DSA-6418-1 thunderbird security update
History

Wed, 22 Jul 2026 12:15:00 +0000


Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla thunderbird
Vendors & Products Mozilla
Mozilla thunderbird

Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 01 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 01 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Description An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.
Title Chat UI manipulation by injection
References

Subscriptions

Mozilla Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-01T14:09:10.035Z

Reserved: 2026-06-26T15:27:32.832Z

Link: CVE-2026-57963

cve-icon Vulnrichment

Updated: 2026-07-01T14:08:57.183Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-01T00:58:33Z

Links: CVE-2026-57963 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:15:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')