Description
An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.
Published: 2026-07-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker who can send HTML chat messages through Matrix or XMPP can and CSS into the Thunderbird chat interface, allowing the attacker to alter the appearance of the chat window and expose users to misleading links or UI confusion.

Affected Systems

Mozilla Thunderbird clients up to version 152.0.0 and 140.12.0 are affected; the fix was applied in Thunderbird 152.0.1 and Thunderbird 140.12.1, and all later releases.

Risk and Exploitability

The CVSS score of 6.5 classifies this vulnerability as Medium severity, with an EPSS score of < 1% and no listing in the CISA KEV catalog. Exploitation requires only that an attacker can send a message via Matrix or XMPP to the victim; it does not enable remote code execution and does not require privileged access. Because the payload is rendered in the user interface, the risk is primarily user phishing links.

Generated by OpenCVE AI on July 15, 2026 at 22:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Thunderbird to version 152.0.1, 140.12.1, or any newer release that includes the fix.
  • Disable HTML rendering for Matrix and XMPP messages in the chat settings so that received messages are treated as plain text.
  • Educate chat messages and avoid clicking suspicious links.

Generated by OpenCVE AI on July 15, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla thunderbird
Vendors & Products Mozilla
Mozilla thunderbird

Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 01 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 01 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Description An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.
Title Chat UI manipulation by injection
References

Subscriptions

Mozilla Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-01T14:09:10.035Z

Reserved: 2026-06-26T15:27:32.832Z

Link: CVE-2026-57963

cve-icon Vulnrichment

Updated: 2026-07-01T14:08:57.183Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T23:00:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')