Protection Mechanism Failure Affecting thunderbird package, versions [,128.13)[140.0-b1,140.1)[141.0-b1,141.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-THUNDERBIRD-10914950
  • published24 Jul 2025
  • disclosed22 Jul 2025
  • creditJoe Turki

Introduced: 22 Jul 2025

NewCVE-2025-8032  (opens in a new tab)
CWE-693  (opens in a new tab)

How to fix?

Upgrade thunderbird to version 128.13, 140.1, 141.0 or higher.

Overview

Affected versions of this package are vulnerable to Protection Mechanism Failure via improper handling of the XSLT document loading process, which failed to correctly propagate the source document and allowed bypassing of content security policy restrictions. An attacker can execute unauthorized scripts or access restricted resources by crafting malicious XSLT documents that are loaded in the affected environment.

CVSS Base Scores

version 4.0
version 3.1