CVE-2020-6809: High severity Mozilla Firefox vulnerability
Last updated 25 August 2025
Other sources
When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to read local files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 74 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 147.0.4-1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-6809?
CVE-2020-6809 is a vulnerability in Mozilla Firefox that allows Web Extensions with the all-urls permission to read local files.
How severe is CVE-2020-6809?
CVE-2020-6809 has a severity value of 4, which is considered medium.
Which versions of Mozilla Firefox are affected by CVE-2020-6809?
Mozilla Firefox versions up to and excluding 74 are affected by CVE-2020-6809.
How can I fix CVE-2020-6809?
To fix CVE-2020-6809, update Mozilla Firefox to version 74 or higher.
Where can I find more information about CVE-2020-6809?
You can find more information about CVE-2020-6809 on the Mozilla Bugzilla website and the Mozilla security advisories page.