User Interface (UI) Misrepresentation of Critical Information Affecting thunderbird package, versions [,128.11.1)[130.0b3,139.0.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (13th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-THUNDERBIRD-10380740
  • published18 Jun 2025
  • disclosed10 Jun 2025
  • creditDario Weißer

Introduced: 10 Jun 2025

CVE-2025-5986  (opens in a new tab)
CWE-451  (opens in a new tab)

How to fix?

Upgrade thunderbird to version 128.11.1, 139.0.2 or higher.

Overview

Affected versions of this package are vulnerable to User Interface (UI) Misrepresentation of Critical Information via the mailbox:/// link handling process. An attacker can cause unsolicited file downloads, exhaust disk space by filling it with arbitrary data, or leak credentials by triggering SMB links when a crafted HTML email is viewed in HTML mode. This is only exploitable if the user views the malicious email in HTML mode and interacts with visually obfuscated download triggers.

CVSS Base Scores

version 4.0
version 3.1