*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9302 | After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 137 and Thunderbird < 137. |
Mon, 13 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 137 and Thunderbird < 137. | After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 137 and Thunderbird 137. |
| Title | Opening local .url files could lead to another file being opened |
Mon, 07 Apr 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla firefox Mozilla thunderbird |
|
| CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mozilla
Mozilla firefox Mozilla thunderbird |
Tue, 01 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-73 | |
| Metrics |
cvssV3_1
|
Tue, 01 Apr 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 137 and Thunderbird < 137. | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-04-13T14:29:35.142Z
Reserved: 2025-03-31T09:35:30.844Z
Link: CVE-2025-3033
Updated: 2025-04-01T18:33:34.355Z
Status : Modified
Published: 2025-04-01T13:15:41.697
Modified: 2026-04-13T15:16:57.157
Link: CVE-2025-3033
No data.
OpenCVE Enrichment
Updated: 2026-04-20T20:45:16Z
EUVD