CVE-2025-1015
Unsanitized address book fields
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 1.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
04 Feb 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant Messaging section. If another user imported the address book, clicking on the link could result in opening a web page inside Thunderbird, and that page could execute (unprivileged) JavaScript. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected products
Mozilla · ThunderbirdWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →