Cross-site scripting in Mozilla Thunderbird - CVE-2026-57963
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to manipulate the chat user interface.
The vulnerability exists due to improper neutralization of HTML content in the chat message rendering component when processing HTML chat messages sent via Matrix or XMPP. A remote attacker can send a crafted HTML chat message containing styled content, phishing links, and CSS to manipulate the chat user interface.
Affected software
Debian Linux
openEuler
thunderbird
thunderbird-debuginfo
thunderbird-debugsource
thunderbird-librnp-rnp
thunderbird-wayland
thunderbird (Debian package)
How to mitigate CVE-2026-57963
thunderbird - update to 140.12.1-1
thunderbird-debuginfo - update to 140.12.1-1
thunderbird-debugsource - update to 140.12.1-1
thunderbird-librnp-rnp - update to 140.12.1-1
thunderbird-wayland - update to 140.12.1-1
thunderbird (Debian package) - update to 1:140.13.0esr-2~deb13u1