CVE-2025-3859
Last modified
CVE-2025-3859 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage. This vulnerability was fixed in Focus 138.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage. This vulnerability was fixed in Focus 138.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox Focus | < 138.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1951533Issue Tracking
- https://www.mozilla.org/security/advisories/mfsa2025-33/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-3859?
How severe is CVE-2025-3859?
How do I fix CVE-2025-3859?
Are you affected by CVE-2025-3859?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
