Skip to main content

CVE-2025-8038: CSP frame-src was not correctly enforced for paths in Mozilla Firefox

Unknown
VulnerabilityCVE-2025-8038cvecve-2025-8038
Published: Tue Jul 22 2025 (07/22/2025, 20:49:26 UTC)
Source: CVE Database V5
Vendor/Project: Mozilla
Product: Firefox

Description

Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

Technical Details

Data Version
5.1
Assigner Short Name
mozilla
Date Reserved
2025-07-22T10:14:06.430Z
Cvss Version
null
State
PUBLISHED

Threat ID: 687ffd51a915ff00f7fb59bf

Added to database: 7/22/2025, 9:06:25 PM

Last updated: 7/22/2025, 9:06:25 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats