Cross-site scripting in Mozilla Thunderbird - CVE-2026-57963

 

Cross-site scripting in Mozilla Thunderbird - CVE-2026-57963

Published: July 22, 2026


Vulnerability identifier: #VU139185
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-57963
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to manipulate the chat user interface.

The vulnerability exists due to improper neutralization of HTML content in the chat message rendering component when processing HTML chat messages sent via Matrix or XMPP. A remote attacker can send a crafted HTML chat message containing styled content, phishing links, and CSS to manipulate the chat user interface.


Affected software

Mozilla Thunderbird
Debian Linux
openEuler
thunderbird
thunderbird-debuginfo
thunderbird-debugsource
thunderbird-librnp-rnp
thunderbird-wayland
thunderbird (Debian package)

How to mitigate CVE-2026-57963

Install security update from vendor's website.

Mozilla Thunderbird - addressed in versions 140.12.1, 152.0.1
thunderbird - update to 140.12.1-1
thunderbird-debuginfo - update to 140.12.1-1
thunderbird-debugsource - update to 140.12.1-1
thunderbird-librnp-rnp - update to 140.12.1-1
thunderbird-wayland - update to 140.12.1-1
thunderbird (Debian package) - update to 1:140.13.0esr-2~deb13u1

External References

Related Security Bulletins