CVE-2025-8032
Last modified
CVE-2025-8032 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 128.13.0 |
| Mozilla | Firefox | < 141.0 |
| Mozilla | Firefox | >= 140.0, < 140.1.0 |
| Mozilla | Thunderbird | < 128.13.0 |
| Mozilla | Thunderbird | < 141.0 |
| Mozilla | Thunderbird | >= 140.0, < 140.1.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1974407Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2025-56/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-58/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-59/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-61/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-62/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-63/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-8032?
How severe is CVE-2025-8032?
How do I fix CVE-2025-8032?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-8025Missing Authentication for Critical Function, Improper Acces…9.8
- CVE-2025-8027On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the …6.5
- CVE-2025-8028On arm64, a WASM `br_table` instruction with a lot of entrie…9.8
- CVE-2025-8029Thunderbird executed `javascript:` URLs when used in `object…8.1
- CVE-2025-8030Insufficient escaping in the “Copy as cURL” feature could po…8.1
- CVE-2025-8031The `username:password` part was not correctly stripped from…9.8
- CVE-2025-8033The JavaScript engine did not handle closed generators corre…6.5
- CVE-2025-8034Memory safety bugs present in Firefox ESR 115.25, Firefox ES…8.8
- CVE-2025-8035Memory safety bugs present in Firefox ESR 128.12, Thunderbir…8.8
- CVE-2025-8036Thunderbird cached CORS preflight responses across IP addres…8.1
- CVE-2025-8037Setting a nameless cookie with an equals sign in the value s…9.1
- CVE-2025-8038Thunderbird ignored paths when checking the validity of navi…9.8
Are you affected by CVE-2025-8032?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
