CVE-2025-2830 Details
Description
By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.
A vulnerability in Mozilla Thunderbird has been identified, allowing for information disclosure by crafting a malformed file name for an attachment in a multipart message. When the message is forwarded or edited as a new one, Thunderbird inadvertently includes a directory listing of the /tmp folder. This issue could lead to the exposure of sensitive information from the user's system. The vulnerability affects Thunderbird versions prior to 137.0.2 and prior to 128.9.2, and is present on both Linux and Windows systems.
Users can upgrade to Thunderbird version 137.0.2 or Thunderbird ESR version 128.9.2 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=1956379 | [email protected] | Permissions Required |
| https://www.mozilla.org/security/advisories/mfsa2025-26/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-27/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mozilla thunderbird | < 128.9.2 >= 129.0, < 137.0.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 13, 2026 | CVE Modified | [email protected] |
| Jun 18, 2025 | Initial Analysis | [email protected] |
| Apr 15, 2025 | CVE Modified | CISA-ADP |
| Apr 15, 2025 | New CVE Received | [email protected] |