CVE-2025-3033High· 7.7▾ TwilightAfter selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in F…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
After selecting a malicious Windows .url shortcut from the local filesystem, an unexpected file could be uploaded.
This bug only affects Firefox on Windows. Other operating systems are unaffected.. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
firefox < 137.0thunderbird < 137.0Upgrade past the affected range:
firefox 137.0thunderbird 137.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-96869Medium· 4.3Information disclosure in the Networking component
CVE-2026-100832High· 8.8Use-after-free in the Graphics: Canvas2D component
CVE-2026-100831High· 8.8Use-after-free in the DOM: UI Events & Focus Handling component
CVE-2026-100830NoneMitigation bypass in the DOM: Navigation component
CVE-2026-100829NoneMitigation bypass in the DOM: Security component
CVE-2026-100828NoneMitigation bypass in the Bookmarks & History component