CVE-2025-6427
critical · 9.1An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
9.1
CVSS
0.3%
EPSS (exploit prob.)
28th
EPSS percentile
2025-06-24
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-693
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| mozilla | firefox | < 140.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-6427