CVE-2025-1015 is a link sanitization vulnerability in Mozilla Thunderbird's Address Book import/export handling. Thunderbird Address Book URI fields could contain unsanitized links, allowing an attacker to craft an address book entry with a malicious payload embedded in a field such as the Instant Messaging section's "Other" field. If the malicious address book were exported and later imported by another user, clicking the embedded link could cause Thunderbird to open attacker-controlled web content inside the application. That page could then execute unprivileged JavaScript within the opened content context. The issue affects Thunderbird versions prior to 128.7 and prior to 135.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository demonstrates a proof-of-concept exploit for CVE-2025-1015, a vulnerability in Mozilla Thunderbird's Address Book. The exploit consists of a Python script (poc.py) that generates a malicious vCard (.vcf) file. The script takes user-supplied HTML or JavaScript as input, encodes it in base64, and embeds it in the IMPP field of the vCard as a data URI. When a victim imports this vCard into Thunderbird and clicks the link, the unsanitized content is rendered, leading to arbitrary JavaScript execution in the context of a webpage within Thunderbird. The repository contains two files: a README.md describing the vulnerability and attack scenario, and poc.py, the exploit generator. The main fingerprintable endpoint is the generated vCard file, specifically the data URI in the IMPP field. The exploit requires social engineering to convince a user to import the malicious address book and interact with the crafted link.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.