CVE-2025-11713
HIGHDescription
Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
Is your site exposed to CVE-2025-11713?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | firefox |
| mozilla | thunderbird |
| mozilla | thunderbird |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2025-11713? +
How severe is CVE-2025-11713? +
What products are affected by CVE-2025-11713? +
How do I check if I'm vulnerable to CVE-2025-11713? +
Related Vulnerabilities
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, due to unsafe handling of the …
GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a …
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - Version Compare Extension allows Cross-Site Scripting (XSS).This …
Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki Core - Feed Utils allows WebView Injection.This issue …
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a normal …