CVE 8.1 HIGH

CVE-2025-8029_CVE-2025-8029

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Description

Firefox executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.

Basic Information

ID CVE-2025-8029
Source mozilla
Published Jul 22, 2025 at 20:49
Modified Jul 31, 2025 at 15:58

Affected Product

Vendor Mozilla
Product Firefox
Version unspecified
Affected Versions Mozilla Firefox unspecified
Mozilla Firefox ESR unspecified
Mozilla Firefox ESR unspecified
Mozilla Thunderbird unspecified
Mozilla Thunderbird unspecified
Mozilla Thunderbird unspecified

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.