CVE-2025-4084 | Mozilla Thunderbird ESR up to 115.22/128.9 on Windows Copy as cURL escape output (Nessus ID 234931 / WID-SEC-2025-1850)
A vulnerability identified as problematic has been detected in Mozilla Thunderbird ESR up to 115.22/128.9 on Windows. Affected is an unknown function of the component Copy as cURL Handler. The manipulation leads to escaping of output.
This vulnerability is traded as CVE-2025-4084. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.