When a file download is specified via the `Content...
Moderate severity
Unreviewed
Published
Jun 26, 2025
to the GitHub Advisory Database
•
Updated Jul 14, 2025
Description
Published by the National Vulnerability Database
Jun 24, 2025
Published to the GitHub Advisory Database
Jun 26, 2025
Last updated
Jul 14, 2025
When a file download is specified via the
Content-Disposition
header, that directive would be ignored if the file was included via a<embed>
or<object>
tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.References