CVE-2025-8038
Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox
Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
CRITICAL · CVSS 9.8
EPSS 0.00195
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules1
YARA rules0