Beveiligingsadvies

CVE-2026-57963

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-01 00:58:33
Laatst bijgewerkt 2026-07-01 14:09:10
Toegewezen door mozilla
CVSS-score 6.5
Status PUBLISHED

Beschrijving

An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.