Mozilla · Thunderbird · CVE-2026-57963
**Name of the Vulnerable Software and Affected Versions**
Thunderbird versions prior to 140.12.1
Thunderbird versions prior to 152.0.1
**Description**
An attacker can inject arbitrary styled content, phishing links, and CSS to manipulate the chat UI by sending HTML chat messages via Matrix or XMPP.
**Recommendations**
Update to version 140.12.1.
Update to version 152.0.1.