CVE-2017-7788: Mozilla Firefox
Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.
When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content Security Policy (CSP) as it should unless the sandbox attribute included "allow-same-origin". This vulnerability affects Firefox < 55.
Affected products
- Mozilla Firefox: before 55.0 (fixed in 55.0)
Published 2018-06-11. Last modified 2026-06-17.