Code Injection in Mozilla Firefox and Firefox ESR - CVE-2025-11713

 

Code Injection in Mozilla Firefox and Firefox ESR - CVE-2025-11713

Published: October 14, 2025 / Updated: April 21, 2026


Vulnerability identifier: #VU116997
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-11713
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation in the “Copy as cURL” feature. A remote attacker can send trick the victim into copying a specially crafted URL and execute arbitrary code on the system.

Note, the vulnerability affects Windows installations only. 


Affected software

Mozilla Firefox
Firefox ESR
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Enterprise Storage
Desktop Applications Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
Mozilla Thunderbird
MozillaFirefox-devel
MozillaFirefox-debuginfo
MozillaFirefox-debugsource
MozillaFirefox-translations-common
MozillaFirefox
MozillaThunderbird-debugsource
MozillaThunderbird-debuginfo
MozillaThunderbird
MozillaThunderbird-translations-other
MozillaThunderbird-translations-common
MozillaFirefox-translations-other
MozillaFirefox-branding-upstream
thunderbird (Ubuntu package)

How to mitigate CVE-2025-11713

Install updates from vendor's website.

Mozilla Firefox - update to 144.0
Firefox ESR - update to 140.4.0
Mozilla Thunderbird - addressed in versions 140.4, 144.0
MozillaFirefox-devel - addressed in versions 140.4.0-112.286.1, 140.4.0-150200.152.207.1, 140.5.0-112.289.1, 140.5.0-150200.152.210.1
MozillaFirefox-debuginfo - addressed in versions 140.4.0-112.286.1, 140.4.0-150200.152.207.1, 140.5.0-112.289.1, 140.5.0-150200.152.210.1
MozillaFirefox-debugsource - addressed in versions 140.4.0-112.286.1, 140.4.0-150200.152.207.1, 140.5.0-112.289.1, 140.5.0-150200.152.210.1
MozillaFirefox-translations-common - addressed in versions 140.4.0-112.286.1, 140.4.0-150200.152.207.1, 140.5.0-112.289.1, 140.5.0-150200.152.210.1
MozillaFirefox - addressed in versions 140.4.0-112.286.1, 140.4.0-150200.152.207.1, 140.5.0-112.289.1, 140.5.0-150200.152.210.1
MozillaThunderbird-debugsource - update to 140.4.0-150200.8.242.1
MozillaThunderbird-debuginfo - update to 140.4.0-150200.8.242.1
MozillaThunderbird - update to 140.4.0-150200.8.242.1
MozillaThunderbird-translations-other - update to 140.4.0-150200.8.242.1
MozillaThunderbird-translations-common - update to 140.4.0-150200.8.242.1
MozillaFirefox-translations-other - addressed in versions 140.4.0-150200.152.207.1, 140.5.0-150200.152.210.1
MozillaFirefox-branding-upstream - addressed in versions 140.4.0-150200.152.207.1, 140.5.0-150200.152.210.1
thunderbird (Ubuntu package) - update to 1:140.7.1+build1-0ubuntu0.22.04.1

External References

Related Security Bulletins