Junglewise Threat Intelligence

CVE-2026-57963: Mozilla Thunderbird HTML and CSS injection in chat component

CVE-2026-57963 · Severity: info · CVSS 6.1 · Published 2026-07-01

Executive brief

Mozilla Thunderbird is a popular email and chat client. A vulnerability in its chat component allows an attacker to send specially crafted messages via Matrix or XMPP that can alter the appearance of the application. This could be used to trick users into clicking malicious phishing links or to hide important security information by manipulating the user interface.

Technical details

A vulnerability in Mozilla Thunderbird's handling of HTML chat messages via Matrix and XMPP protocols allows for arbitrary styled content injection. By sending malicious HTML and CSS, an attacker can bypass intended UI constraints to inject phishing links or manipulate the chat interface (CSS injection). This is likely due to insufficient sanitization of incoming chat payloads before rendering. The issue is resolved in Thunderbird versions 152.0.1 and 140.12.1.

Affected products

  • Mozilla Thunderbird versions prior to 152.0.1 and 140.12.1

Timeline

  • 2026-06-30: patched: Fixed in Thunderbird 152.0.1 and 140.12.1
  • 2026-07-01: disclosed: NVD publication date

References

Related threats