Loading HuntDB...

GHSA-xmc5-26p9-v4x6

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.

Related CVEs

Key Information

GHSA ID
GHSA-xmc5-26p9-v4x6
Published
May 14, 2022 3:09 AM
Last Modified
May 14, 2022 3:09 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 14, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.