Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*, +1 more
- < 139
A vulnerability exists in Mozilla Firefox versions prior to 139, as well as in Firefox ESR versions prior to 115.24 and 128.11. The issue arises from inadequate escaping of the newline character in the 'Copy as cURL' feature. This flaw could enable an attacker to manipulate a user into executing a crafted cURL command, potentially leading to local code execution on the user's system.
Exploitation of this vulnerability could result in unauthorized local code execution on the user's system.
Users can upgrade to Firefox 139, Firefox ESR 115.24, or Firefox ESR 128.11 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.