CVE-2025-1015
Unsanitized address book fields
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malicious payload in a field. For example, in the βOtherβ field of the Instant Messaging section. If another user imported the address book, clicking on the link could result in opening a web page inside Thunderbird, and that page could execute (unprivileged) JavaScript. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.
| Vendor | mozilla |
| Product | thunderbird |
| Ecosystems | |
| Industries | Technology |
| Published | Feb 4, 2025 |
| Last Updated | Apr 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for mozilla thunderbird
Be the first to know when new medium vulnerabilities affecting mozilla thunderbird are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
Mozilla / Thunderbird
All versions affected References
Credits
r3m0t3nu11