{"id":"CVE-2025-65318","title":"When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS…","summary":"When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-693"],"vendor":"canarymail","product":"canary_mail","affected":["canary_mail <= 5.1.40"],"published":"2025-12-16","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-65318","references":[{"url":"https://drive.google.com/file/d/14wrTzvcLPfFsWmy-SAtDwwZKKPssBsx5/view","label":"cve@mitre.org"},{"url":"https://github.com/bbaboha/CVE-2025-65318-and-CVE-2025-65319","label":"cve@mitre.org"},{"url":"https://github.com/nickvourd/RTI-Toolkit","label":"cve@mitre.org"},{"url":"https://github.com/bbaboha/CVE-2025-65318-and-CVE-2025-65319","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available"],"epss":0.0056,"epssPercentile":0.45413,"ingestedAt":"2026-07-06T16:44:34.486Z","exploits":{"github":1,"githubRepos":["https://github.com/bbaboha/CVE-2025-65318-and-CVE-2025-65319"],"checkedAt":"2026-09-24T07:52:54.036Z"},"exploitAvailable":true,"slug":"CVE-2025-65318","body":"## Overview\n\nWhen using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS and third-party software.\n\n## Affected\n\n- `canary_mail <= 5.1.40`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":62,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":4857,"id":"CVE-2025-65318","ts":1788887212145,"field":"exploit_available","old":"false","new":"true"},{"seq":3740,"id":"CVE-2025-65318","ts":1788886328747,"field":"exploit_available","old":"true","new":"false"},{"seq":2585,"id":"CVE-2025-65318","ts":1788883009828,"field":"exploit_available","old":"false","new":"true"},{"seq":1614,"id":"CVE-2025-65318","ts":1788882410135,"field":"exploit_available","old":"true","new":"false"},{"seq":725,"id":"CVE-2025-65318","ts":1788881847366,"field":"exploit_available","old":"false","new":"true"}]}