Cross-site scripting in Mozilla Thunderbird - CVE-2026-57963
Published: July 22, 2026
Mozilla Thunderbird
Detailed vulnerability description
The vulnerability allows a remote attacker to manipulate the chat user interface.
The vulnerability exists due to improper neutralization of HTML content in the chat message rendering component when processing HTML chat messages sent via Matrix or XMPP. A remote attacker can send a crafted HTML chat message containing styled content, phishing links, and CSS to manipulate the chat user interface.