CVE Vulnerabilities

CVE-2025-3909

Product UI does not Warn User of Unsafe Actions

Published: May 14, 2025 | Modified: Feb 26, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Thunderbirds handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may incorrectly render it as HTML when opened, allowing the embedded JavaScript to run without requiring a file download. This behavior relies on Thunderbird auto-saving the attachment to /tmp and linking to it via the file:/// protocol, potentially enabling JavaScript execution as part of the HTML. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.

Weakness

The product’s user interface does not warn the user before undertaking an unsafe action on behalf of that user. This makes it easier for attackers to trick users into inflicting damage to their system.

Affected Software

NameVendorStart VersionEnd Version
ThunderbirdMozilla*128.10.1 (excluding)
ThunderbirdMozilla129.0 (including)138.0.1 (excluding)
Red Hat Enterprise Linux 10RedHatthunderbird-0:128.10.1-1.el10_0*
Red Hat Enterprise Linux 8RedHatthunderbird-0:128.11.0-1.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatthunderbird-0:128.10.1-1.el8_2*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatthunderbird-0:128.10.1-1.el8_4*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatthunderbird-0:128.10.1-1.el8_6*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatthunderbird-0:128.10.1-1.el8_6*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatthunderbird-0:128.10.1-1.el8_6*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatthunderbird-0:128.10.1-1.el8_8*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatthunderbird-0:128.10.1-1.el8_8*
Red Hat Enterprise Linux 9RedHatthunderbird-0:128.10.1-1.el9_6*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatthunderbird-0:128.10.1-1.el9_0*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatthunderbird-0:128.10.1-1.el9_2*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatthunderbird-0:128.10.1-1.el9_4*
ThunderbirdUbuntufocal*
ThunderbirdUbuntujammy*
ThunderbirdUbuntuoracular*
ThunderbirdUbuntuupstream*

References