CVE-2025-5271

Publication date

2025-05-27 12:29:29

Family

mozilla

State

PUBLISHED

Description

Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerability affects Firefox < 139 and Thunderbird < 139.