CVE-2025-8032 | Mozilla Thunderbird up to 140 XSLT Document cross-domain policy
A vulnerability, which was classified as problematic, was found in Mozilla Thunderbird up to 140. Affected is an unknown function of the component XSLT Document Handler. The manipulation leads to permissive cross-domain policy with untrusted domains.
This vulnerability is traded as CVE-2025-8032. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.