Cross-site scripting in Mozilla Thunderbird - CVE-2026-57963

 

Cross-site scripting in Mozilla Thunderbird - CVE-2026-57963

Published: July 22, 2026


Vulnerability identifier: #VU139185
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Green
CVE-ID: CVE-2026-57963
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Mozilla
Affected software:
Mozilla Thunderbird

Detailed vulnerability description

The vulnerability allows a remote attacker to manipulate the chat user interface.

The vulnerability exists due to improper neutralization of HTML content in the chat message rendering component when processing HTML chat messages sent via Matrix or XMPP. A remote attacker can send a crafted HTML chat message containing styled content, phishing links, and CSS to manipulate the chat user interface.


How to mitigate CVE-2026-57963

Install security update from vendor's website.

Sources