CVE-2025-11940 Details
Description
A security vulnerability has been detected in LibreWolf up to 143.0.4-1 on Windows. This affects an unknown function of the file assets/setup.nsi of the component Installer. Such manipulation leads to uncontrolled search path. The attack must be carried out locally. Attacks of this nature are highly complex. The exploitability is reported as difficult. Upgrading to version 144.0-1 mitigates this issue. The name of the patch is dd10e31dd873e9cb309fad8aed921d45bf905a55. It is suggested to upgrade the affected component.
A vulnerability in the LibreWolf installer for Windows, specifically in versions prior to 144.0-1, has been identified. This issue arises from an uncontrolled search path in the installation process, allowing for EXE hijacking. When the installer is executed, it looks for a missing executable named 'schtasks.exe' in the same directory as the installer. If a malicious executable with that name is placed in the folder before installation, the LibreWolf installer will automatically execute it after the installation is complete. This vulnerability could be exploited to run arbitrary commands with the same privileges as the user who installed the browser, potentially compromising data or altering system functionality.
Users are advised to upgrade to LibreWolf version 144.0-1, which addresses this vulnerability. The updated version can be downloaded from the LibreWolf GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 19, 2025CISA-ADP
Assessed Oct 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Cyber-Wo0dy/report/blob/main/librewolf/143.0.4-1/librewolf_installer_exe_hijacking.md | CISA-ADP | ExploitTechnical Description |
| https://vuldb.com/?submit.671575 | CISA-ADP | ExploitTechnical Description |
| https://codeberg.org/librewolf/bsys6/commit/dd10e31dd873e9cb309fad8aed921d45bf905a55 | [email protected] | Source CodeVendor |
| https://codeberg.org/librewolf/bsys6/releases/tag/144.0-1 | [email protected] | Release NotesVendor |
| https://github.com/Cyber-Wo0dy/report/blob/main/librewolf/143.0.4-1/librewolf_installer_exe_hijacking.md | [email protected] | ExploitTechnical Description |
| https://vuldb.com/?ctiid.329019 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.329019 | [email protected] | AdvisoryRemedy |
| https://vuldb.com/?submit.671575 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-426 | Untrusted Search Path | [email protected] |
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| LibreWolf | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 20, 2025 | CVE Modified | CISA-ADP |
| Oct 19, 2025 | New CVE Received | [email protected] |
Volerion