CVE-2025-11713: Mozilla Firefox
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
Affected products
- Mozilla Firefox: before 140.4.0 (fixed in 140.4.0); before 144.0 (fixed in 144.0)
- Mozilla Thunderbird: before 140.4.0 (fixed in 140.4.0); from 141.0, before 144.0 (fixed in 144.0)
Published 2025-10-14. Last modified 2026-06-17.