CVE-2025-13015
LOWCVSS 3.4/10EPSS 0.22%
Last modified
CVE-2025-13015 is a low-severity vulnerability rated 3.4/10 on the CVSS scale. Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 115.30.0 |
| Mozilla | Firefox | < 145.0 |
| Mozilla | Firefox | >= 140.0, < 140.5.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1994164Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2025-87/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-88/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-89/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-13015?
Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30.
How severe is CVE-2025-13015?
CVE-2025-13015 has a CVSS score of 3.4/10 (LOW severity). The EPSS model estimates a 0.22% probability of exploitation in the next 30 days.
How do I fix CVE-2025-13015?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-13007The WP Social Ninja – Embed Social Feeds, Customer Reviews, …6.1
- CVE-2025-13008An information disclosure vulnerability in M-Files Server be…8.6
- CVE-2025-1301Improper Neutralization of Input During Web Page Generation …6.1
- CVE-2025-13012Race condition in the Graphics component. This vulnerability…7.5
- CVE-2025-13013Mitigation bypass in the DOM: Core & HTML component. This vu…6.1
- CVE-2025-13014Use-after-free in the Audio/Video component. This vulnerabil…8.8
- CVE-2025-13016Incorrect boundary conditions in the JavaScript: WebAssembly…7.5
- CVE-2025-13017Same-origin policy bypass in the DOM: Notifications componen…8.1
- CVE-2025-13018Mitigation bypass in the DOM: Security component. This vulne…8.1
- CVE-2025-13019Same-origin policy bypass in the DOM: Workers component. Thi…8.1
- CVE-2025-1302Versions of the package jsonpath-plus before 10.3.0 are vuln…9.8
- CVE-2025-13020Use-after-free in the WebRTC: Audio/Video component. This vu…8.8
Are you affected by CVE-2025-13015?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
