Mozilla Firefox and Thunderbird XSS Vulnerability via OBJECT Tag Type Attribute

Vulnerability

A vulnerability exists in Mozilla Firefox versions prior to 144, Firefox ESR versions prior to 140.4, Thunderbird versions prior to 144, and Thunderbird ESR versions prior to 140.4. A malicious page could exploit the type attribute of an OBJECT tag to alter the default browser behavior when handling web resources that lack a content-type. This manipulation could have facilitated a cross-site scripting (XSS) attack on websites that improperly serve files without a content-type header.

Impact

Exploitation of this vulnerability could have led to a cross-site scripting (XSS) attack on affected sites.

Remediation

Users can upgrade to Firefox 144, Firefox ESR 140.4, Thunderbird 144, or Thunderbird ESR 140.4 to address this vulnerability.

Added: Oct 14, 2025, 1:31 PM
Updated: Oct 14, 2025, 11:44 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
1.7
exploitability
4.4
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.