CVE-2025-6429
Estado: ModificadaMedia (6.5)—
Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.36%
- Percentil entre todas las CVEs puntuadas: 27
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-116
Referencias
- https://bugzilla.mozilla.org/show_bug.cgi?id=1970658
- https://www.mozilla.org/security/advisories/mfsa2025-51/
- https://www.mozilla.org/security/advisories/mfsa2025-53/
- https://www.mozilla.org/security/advisories/mfsa2025-54/
- https://www.mozilla.org/security/advisories/mfsa2025-55/
- https://lists.debian.org/debian-lts-announce/2025/06/msg00029.html
- https://lists.debian.org/debian-lts-announce/2025/07/msg00002.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-6429",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-6429",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-06-25T14:21:21.354270Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@mozilla.org",
"affectedData": [
{
"vendor": "Mozilla",
"product": "Firefox",
"versions": [
{
"status": "unaffected",
"version": "128.12",
"versionType": "rpm",
"lessThanOrEqual": "128.*"
},
{
"status": "unaffected",
"version": "140",
"versionType": "rpm",
"lessThanOrEqual": "*"
}
]
},
{
"vendor": "Mozilla",
"product": "Thunderbird",
"versions": [
{
"status": "unaffected",
"version": "128.12",
"versionType": "rpm",
"lessThanOrEqual": "128.*"
},
{
"status": "unaffected",
"version": "140",
"versionType": "rpm",
"lessThanOrEqual": "*"
}
]
}
]
}
],
"published": "2025-06-24T13:15:23.877",
"references": [
{
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1970658",
"tags": [
"Permissions Required"
],
"source": "security@mozilla.org"
},
{
"url": "https://www.mozilla.org/security/advisories/mfsa2025-51/",
"tags": [
"Vendor Advisory"
],
"source": "security@mozilla.org"
},
{
"url": "https://www.mozilla.org/security/advisories/mfsa2025-53/",
"tags": [
"Vendor Advisory"
],
"source": "security@mozilla.org"
},
{
"url": "https://www.mozilla.org/security/advisories/mfsa2025-54/",
"source": "security@mozilla.org"
},
{
"url": "https://www.mozilla.org/security/advisories/mfsa2025-55/",
"source": "security@mozilla.org"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2025/06/msg00029.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2025/07/msg00002.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-116"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12."
},
{
"lang": "es",
"value": "Firefox podría haber analizado incorrectamente una URL y reescrito el dominio youtube.com al analizar la URL especificada en una etiqueta 'embed'. Esto podría haber eludido las comprobaciones de seguridad del sitio web que restringían los dominios que los usuarios podían incrustar. Esta vulnerabilidad afecta a Firefox con versiones anteriores a 140 y Firefox con ESR inferior a 128.12."
}
],
"lastModified": "2026-09-30T18:10:00.190",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"vulnerable": true,
"matchCriteriaId": "18420C6D-A5DF-41A4-8A81-F1BBFBA1BE2A",
"versionEndExcluding": "128.12.0"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "77D2BF2A-26A3-4664-93B5-B41BCF17AC9E",
"versionEndExcluding": "140.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@mozilla.org"
}