CVE-2025-65318: Critical severity Canary Mail Canary Mail vulnerability
When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS and third-party software.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65318?
CVE-2025-65318 is considered a high severity vulnerability due to its ability to allow attackers to bypass file protection mechanisms.
How do I fix CVE-2025-65318?
To fix CVE-2025-65318, users should upgrade to a version of Canary Mail above 5.1.40.
What are the risks associated with CVE-2025-65318?
The risks associated with CVE-2025-65318 include potential unauthorized access to sensitive documents due to the lack of a Mark-of-the-Web tag.
Which versions of Canary Mail are affected by CVE-2025-65318?
CVE-2025-65318 affects Canary Mail versions 5.1.40 and below.
What is the Mark-of-the-Web tag in relation to CVE-2025-65318?
The Mark-of-the-Web tag is a security feature that helps identify documents downloaded from the internet and applies file protection measures, which are bypassed in CVE-2025-65318.