Mozilla Firefox and Thunderbird XSLT Document Loading CSP Bypass Vulnerability

Vulnerability

A vulnerability exists in Mozilla Firefox and Thunderbird due to improper handling of XSLT document loading, which can lead to a bypass of Content Security Policy (CSP) restrictions. This issue is present in Firefox versions prior to 141, Firefox ESR versions prior to 128.13 and 140.1, as well as Thunderbird versions prior to 141, 128.13 and 140.1.

Impact

Exploitation of this vulnerability allows for a bypass of Content Security Policy, which could lead to unauthorized script execution or resource loading.

Remediation

Users can upgrade to Firefox 141, Firefox ESR 128.13 or 140.1, or Thunderbird 141, 128.13 or 140.1 to address this vulnerability.

Added: Jul 22, 2025, 9:41 PM
Updated: Jul 22, 2025, 9:41 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
1.3
exploitability
4.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.