CVE-2020-6811: Command Injection
Last updated 25 August 2025
Other sources
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-6811?
CVE-2020-6811 is a vulnerability in Mozilla Firefox and Thunderbird that allows command injection and arbitrary command execution.
How does CVE-2020-6811 work?
CVE-2020-6811 works by not properly escaping the HTTP method of a request in the 'Copy as cURL' feature of Devtools' network tab.
Which software is affected by CVE-2020-6811?
Mozilla Firefox (up to version 74), Thunderbird (up to version 68.6), and Firefox ESR (up to version 68.6) are affected by CVE-2020-6811.
What is the severity of CVE-2020-6811?
The severity of CVE-2020-6811 is rated as medium.
How can I fix CVE-2020-6811?
To fix CVE-2020-6811, update Mozilla Firefox to version 75 or later, Thunderbird to version 68.7 or later, or Firefox ESR to version 68.7 or later.