CVE-2025-2830
Information Disclosure of /tmp directory listing
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.
| Vendor | mozilla |
| Product | thunderbird |
| Ecosystems | |
| Industries | Technology |
| Published | Apr 15, 2025 |
| Last Updated | Apr 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for mozilla thunderbird
Be the first to know when new medium vulnerabilities affecting mozilla thunderbird are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
Mozilla / Thunderbird
All versions affected References
Credits
Dario WeiΓer