Back

MEDIUM

Unsanitized address book fields

Published Feb 4, 2025

Description

The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant Messaging section. If another user imported the address book, clicking on the link could result in opening a web page inside Thunderbird, and that page could execute (unprivileged) JavaScript. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.

Affected products

Remediation

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Feb 4, 2025
Updated Apr 13, 2026
Reserved Feb 4, 2025
CISA Vulnrichment
Updated Feb 6, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 4, 2025