Due to insufficient escaping of the ampersand character...
Moderate severity
Unreviewed
Published
May 27, 2025
to the GitHub Advisory Database
•
Updated Jun 11, 2025
Description
Published by the National Vulnerability Database
May 27, 2025
Published to the GitHub Advisory Database
May 27, 2025
Last updated
Jun 11, 2025
Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system.
This bug only affects Firefox for Windows. Other versions of Firefox are unaffected. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.
References