firefox is vulnerable to content security policy bypass. The application does not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass.
access.redhat.com/security/cve/cve-2020-26958
bugzilla.mozilla.org/show_bug.cgi?id=1669355
www.mozilla.org/en-US/security/advisories/mfsa2020-51/#CVE-2020-26958
www.mozilla.org/security/advisories/mfsa2020-50/
www.mozilla.org/security/advisories/mfsa2020-51/
www.mozilla.org/security/advisories/mfsa2020-52/