CVE-2026-6755

· NIST NVD ↗

Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

MEDIUM
CVSS severity
6.5
CVSS base score
2026-04-21
Published

CWE codes

CWE-352

Affected products

mozilla:firefoxmozilla:thunderbird

Sources