CVE-2025-11713
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/10/2025
Last modified:
14/11/2025
Description
Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability affects Firefox
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | 140.4.0 (excluding) | |
| cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | 144.0 (excluding) | |
| cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | 140.4.0 (excluding) | |
| cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | 141.0 (including) | 144.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



