CVE-2025-6427
NixOS vulnerability analysis and mitigation

Overview

A Content Security Policy (CSP) bypass vulnerability was discovered in Firefox versions prior to 140, identified as CVE-2025-6427. The vulnerability was reported by security researcher Alan Li (lebr0nli) and was publicly disclosed on June 24, 2025. The issue affects the connect-src directive implementation in Firefox's Content Security Policy mechanism (Mozilla Advisory, NVD).

Technical details

The vulnerability allows an attacker to bypass the connect-src directive of a Content Security Policy by manipulating subdocuments. A notable aspect of this vulnerability is that it also conceals the unauthorized connections from the Network tab in Firefox's Developer Tools, making detection more difficult. The vulnerability has been assigned a CVSS v3.1 base score of 9.1 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, indicating high severity with potential for significant impact (NVD).

Impact

The vulnerability has been rated as having a moderate impact by Mozilla. The bypass of the Content Security Policy's connect-src directive could allow attackers to make unauthorized network connections from affected web pages, potentially leading to data exfiltration or unauthorized resource access. The ability to hide these connections from the Developer Tools further complicates detection and incident response efforts (Mozilla Advisory).

Mitigation and workarounds

The vulnerability has been fixed in Firefox version 140. Users and administrators are advised to upgrade to Firefox 140 or later to protect against this security issue. No alternative workarounds have been publicly documented (Mozilla Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management