---
id: CVE-2025-8032
title: >-
  XSLT document loading did not correctly propagate the source document which
  bypassed its CSP
summary: >-
  XSLT document loading did not correctly propagate the source document which
  bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR
  128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and
  Thunderbird 140.1.
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-693
vendor: mozilla
product: firefox
affected:
  - firefox < 128.13.0
  - firefox < 141.0
  - 'firefox >= 140.0, < 140.1.0'
  - thunderbird < 128.13.0
  - thunderbird < 141.0
  - 'thunderbird >= 140.0, < 140.1.0'
patched:
  - firefox 140.1.0
  - thunderbird 140.1.0
published: '2025-07-22'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T18:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8032'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1974407'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-56/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-58/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-59/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-61/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-62/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-63/'
    label: security@mozilla.org
  - url: 'https://lists.debian.org/debian-lts-announce/2025/07/msg00016.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00329
epssPercentile: 0.23578
ingestedAt: '2026-09-30T18:17:24.448Z'
---

## Overview

XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.

## Affected

- `firefox < 128.13.0`
- `firefox < 141.0`
- `firefox >= 140.0, < 140.1.0`
- `thunderbird < 128.13.0`
- `thunderbird < 141.0`
- `thunderbird >= 140.0, < 140.1.0`

## Remediation

Upgrade past the affected range:

- `firefox 140.1.0`
- `thunderbird 140.1.0`
