CVE-2025-8029

Publication date

2025-07-22 20:49:24

Family

mozilla

State

PUBLISHED

Description

Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.