CVE-2025-14331

Discovered by AISLEPUBLISHED

Description

Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

CVSS Base Scores

CVSS v3.1(Primary)
6.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionStatus
MozillaFirefox115.31unaffected
MozillaFirefox140.6
MozillaFirefox146
MozillaThunderbird115.31unaffected
MozillaThunderbird140.6
MozillaThunderbird146

Credits

  • Igor Morgenstern

References