| Name | CVE-2025-11713 |
| Description | Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| firefox (PTS) | sid | 150.0-1 | fixed |
| firefox-esr (PTS) | bullseye | 115.14.0esr-1~deb11u1 | fixed |
| bullseye (security) | 140.10.0esr-1~deb11u1 | fixed | |
| bookworm | 128.14.0esr-1~deb12u1 | fixed | |
| bookworm (security) | 140.10.0esr-1~deb12u1 | fixed | |
| trixie | 140.8.0esr-1~deb13u1 | fixed | |
| trixie (security) | 140.10.0esr-1~deb13u1 | fixed | |
| forky | 140.9.1esr-1 | fixed | |
| sid | 140.10.0esr-1 | fixed | |
| thunderbird (PTS) | bullseye | 1:115.12.0-1~deb11u1 | fixed |
| bullseye (security) | 1:140.10.0esr-1~deb11u1 | fixed | |
| bookworm | 1:140.6.0esr-1~deb12u1 | fixed | |
| bookworm (security) | 1:140.10.0esr-1~deb12u1 | fixed | |
| trixie | 1:140.8.0esr-1~deb13u1 | fixed | |
| trixie (security) | 1:140.10.0esr-1~deb13u1 | fixed | |
| forky | 1:140.9.1esr-1 | fixed | |
| sid | 1:140.10.0esr-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| firefox | source | (unstable) | (not affected) | |||
| firefox-esr | source | (unstable) | (not affected) | |||
| thunderbird | source | (unstable) | (not affected) |
- firefox <not-affected> (Only affects Firefox on Windows)
- firefox-esr <not-affected> (Only affects Firefox ESR on Windows)
- thunderbird <not-affected> (Only affects Thunderbird on Windows)
https://www.mozilla.org/en-US/security/advisories/mfsa2025-81/#CVE-2025-11713
https://www.mozilla.org/en-US/security/advisories/mfsa2025-83/#CVE-2025-11713
https://www.mozilla.org/en-US/security/advisories/mfsa2025-85/#CVE-2025-11713