Mozilla Firefox and Firefox ESR Newline Injection Vulnerability in 'Copy as cURL' Feature Allowing Local Code Execution

Vulnerability

A vulnerability exists in Mozilla Firefox versions prior to 139, as well as in Firefox ESR versions prior to 115.24 and 128.11. The issue arises from inadequate escaping of the newline character in the 'Copy as cURL' feature. This flaw could enable an attacker to manipulate a user into executing a crafted cURL command, potentially leading to local code execution on the user's system.

Impact

Exploitation of this vulnerability could result in unauthorized local code execution on the user's system.

Remediation

Users can upgrade to Firefox 139, Firefox ESR 115.24, or Firefox ESR 128.11 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.