An attacker was able to bypass the `connect-src`...
Critical severity
Unreviewed
Published
Jun 26, 2025
to the GitHub Advisory Database
•
Updated Jul 14, 2025
Description
Published by the National Vulnerability Database
Jun 24, 2025
Published to the GitHub Advisory Database
Jun 26, 2025
Last updated
Jul 14, 2025
An attacker was able to bypass the
connect-src
directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140.References