---
id: CVE-2025-4088
title: >-
  A security vulnerability in Thunderbird allowed malicious sites to use
  redirects to send credentialed requests to arbitrary endpoints on any site
  that had invoked the Storage Access API
summary: >-
  A security vulnerability in Thunderbird allowed malicious sites to use
  redirects to send credentialed requests to arbitrary endpoints on any site
  that had invoked the Storage Access API. This enabled potential Cross-Site
  Request Forgery …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-352
vendor: mozilla
product: firefox
affected:
  - firefox < 138.0
  - thunderbird < 138.0
patched:
  - firefox 138.0
  - thunderbird 138.0
published: '2025-04-29'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T18:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-4088'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1953521'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-28/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-31/'
    label: security@mozilla.org
tags:
  - nvd
epss: 0.00175
epssPercentile: 0.06324
ingestedAt: '2026-09-30T18:17:24.435Z'
---

## Overview

A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability was fixed in Firefox 138 and Thunderbird 138.

## Affected

- `firefox < 138.0`
- `thunderbird < 138.0`

## Remediation

Upgrade past the affected range:

- `firefox 138.0`
- `thunderbird 138.0`
