CVE-2018-5135: Mozilla Firefox

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject scripts into contexts where this should not be allowed, such as pages from other WebExtensions or unprivileged "about:" pages. This vulnerability affects Firefox < 59.

Affected products

  • Mozilla Firefox: before 59.0 (fixed in 59.0)

Published 2018-06-11. Last modified 2026-06-17.