← back
CVE-2023-23599

Malicious command could be hidden in devtools output on Windows

EPSS 0.6%
When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →