CVE-2025-3932
Last modified
CVE-2025-3932 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Thunderbird | < 128.10.1 |
| Mozilla | Thunderbird | >= 129.0, < 138.0.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-3932?
How severe is CVE-2025-3932?
How do I fix CVE-2025-3932?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-3925BrightSign players running BrightSign OS series 4 prior to v…8.5
- CVE-2025-3927Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not…9.8
- CVE-2025-3928Commvault Web Server has an unspecified vulnerability that c…8.8
- CVE-2025-3929An XSS issue was discovered in MDaemon Email Server version …6.1
- CVE-2025-3930Strapi uses JSON Web Tokens (JWT) for authentication. After …6.3
- CVE-2025-3931A flaw was found in Yggdrasil, which acts as a system broker…7.8
- CVE-2025-3933A Regular Expression Denial of Service (ReDoS) vulnerability…5.3
- CVE-2025-39348Deserialization of Untrusted Data vulnerability in ThemeGood…9.8
- CVE-2025-39349Deserialization of Untrusted Data vulnerability in Potenzagl…9.8
- CVE-2025-3935ScreenConnect versions 25.2.3 and earlier versions may be su…7.2
- CVE-2025-39350Missing Authorization vulnerability in Rocket Apps wProject.…8.2
- CVE-2025-39351Cross-Site Request Forgery (CSRF) vulnerability in ThemeGood…4.3
Are you affected by CVE-2025-3932?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
