CVE-2025-3523 Details
Description
When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.
A vulnerability exists in Mozilla Thunderbird versions prior to 137.0.2 and Thunderbird ESR versions prior to 128.9.2, where the email client misrepresents attachment URLs in the user interface. When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is displayed when hovering over any attachment. Although the correct link is used when the attachment is clicked, this inconsistency could mislead users into downloading content from untrusted sources.
Users can upgrade to Mozilla Thunderbird version 137.0.2 or Thunderbird ESR version 128.9.2 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=1958385 | [email protected] | Permissions Required |
| https://www.mozilla.org/security/advisories/mfsa2025-26/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-27/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-451 | User Interface (UI) Misrepresentation of Critical Information | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mozilla thunderbird | < 128.9.2 >= 129.0, < 137.0.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 13, 2026 | CVE Modified | [email protected] |
| Jun 13, 2025 | Initial Analysis | [email protected] |
| Apr 15, 2025 | CVE Modified | CISA-ADP |
| Apr 15, 2025 | New CVE Received | [email protected] |