CVE-2020-12393
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-12393 is a security vulnerability discovered in Firefox's DevTools 'Copy as cURL' feature. The vulnerability was reported by David Yesland and disclosed on May 5, 2020. It affects Firefox versions prior to 76 and Firefox ESR versions prior to 68.8, specifically impacting Windows operating systems (Mozilla Advisory).

Technical details

The vulnerability stems from improper escaping of the HTTP method in the 'Copy as cURL' feature of Firefox's DevTools network tab. When a website controls the HTTP method of a request, the lack of proper escaping of special characters, particularly the dollar sign ($), could lead to potential command injection. The vulnerability was assigned a moderate severity rating (Mozilla Advisory, Bugzilla).

Impact

If exploited, this vulnerability could result in command injection and arbitrary command execution when a user copies a malicious request using the 'Copy as cURL' feature and pastes it into a terminal. The impact is limited to Windows operating systems and requires user interaction (Mozilla Advisory).

Exploitability

The vulnerability can be exploited by creating a request containing unencoded $() characters in portions that don't get URL encoded, such as HTTP headers. When such a request is copied using 'Copy as cURL (Windows)' and pasted into PowerShell, it could lead to command execution (Bugzilla).

Mitigation and workarounds

The vulnerability was patched in Firefox 76 and Firefox ESR 68.8. The fix involved properly escaping the dollar sign for curl commands on Windows to prevent command injection possibilities (Bugzilla).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • gcc10-binutils
NoYesSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • gcc-toolset-16-binutils.src
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management