Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | - | 140.4.0 |
| mozilla / firefox | - | 144.0 |
| mozilla / thunderbird | - | 140.4.0 |
| mozilla / thunderbird | 141.0 | 144.0 |