CVE-2017-7788: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content Security Policy (CSP) as it should unless the sandbox attribute included "allow-same-origin". This vulnerability affects Firefox < 55.

Affected products

  • Mozilla Firefox: before 55.0 (fixed in 55.0)

Published 2018-06-11. Last modified 2026-06-17.