#VU109192 Input validation error in Mozilla Thunderbird - CVE-2025-3909
Published: May 14, 2025
Mozilla Thunderbird
Mozilla
Description
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to incorrect handling of the X-Mozilla-External-Attachment-URL header. A remote attacker can create a nested email attachment, set its content type to application/pdf and force the application to execute arbitrary JavaScript code in the file:/// context.