← All CVEs

CVE-2025-6427

critical · 9.1

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

9.1
CVSS
0.3%
EPSS (exploit prob.)
28th
EPSS percentile
2025-06-24
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-693

Affected products

VendorProductAffected versions
mozillafirefox< 140.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-6427