CVE-2025-65318
EUVD-2025-20380716.12.2025, 16:15
When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS and third-party software.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| canarymail | canary_mail | 𝑥 ≤ 5.1.40 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration