Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2.
References
| Link | Resource |
|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=2043878 | Permissions Required |
| https://www.mozilla.org/security/advisories/mfsa2026-78/ | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2026-88/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-09-01 22:17
Updated : 2026-09-03 19:02
NVD link : CVE-2026-84637
Mitre link : CVE-2026-84637
CVE.ORG link : CVE-2026-84637
JSON object : View
Products Affected
mozilla
- thunderbird
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
