CVE-2025-65318: n/a
When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS and third-party software.
AI Analysis
Technical Summary
The vulnerability CVE-2025-65318 affects Canary Mail up to version 5.1.40. When users interact with attachments, the application saves these files without embedding the Mark-of-the-Web tag, a security feature used by Windows and some third-party software to identify files downloaded from the internet or other untrusted sources. Without this tag, the files are treated as trusted, enabling attackers to circumvent built-in protections that would normally warn users or restrict file execution. The CVSS v3.1 base score is 9.1, indicating a critical severity with network attack vector, low attack complexity, no privileges or user interaction required, and high confidentiality and integrity impact.
Potential Impact
Attackers can exploit this vulnerability to bypass Windows and third-party file protection mechanisms by delivering malicious attachments that are saved without the Mark-of-the-Web tag. This increases the risk of executing malicious files without warning, potentially leading to unauthorized disclosure or modification of sensitive information. There is no known exploitation in the wild at this time.
Mitigation Recommendations
No official patch or fix information is currently available for this vulnerability. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, users should exercise caution when handling attachments in Canary Mail, especially from untrusted sources. Consider using additional endpoint protection solutions that do not rely solely on Mark-of-the-Web tags for file trust decisions.
CVE-2025-65318: n/a
Description
When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS and third-party software.
CVSS v3.1
Score 9.1critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2025-65318 affects Canary Mail up to version 5.1.40. When users interact with attachments, the application saves these files without embedding the Mark-of-the-Web tag, a security feature used by Windows and some third-party software to identify files downloaded from the internet or other untrusted sources. Without this tag, the files are treated as trusted, enabling attackers to circumvent built-in protections that would normally warn users or restrict file execution. The CVSS v3.1 base score is 9.1, indicating a critical severity with network attack vector, low attack complexity, no privileges or user interaction required, and high confidentiality and integrity impact.
Potential Impact
Attackers can exploit this vulnerability to bypass Windows and third-party file protection mechanisms by delivering malicious attachments that are saved without the Mark-of-the-Web tag. This increases the risk of executing malicious files without warning, potentially leading to unauthorized disclosure or modification of sensitive information. There is no known exploitation in the wild at this time.
Mitigation Recommendations
No official patch or fix information is currently available for this vulnerability. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, users should exercise caution when handling attachments in Canary Mail, especially from untrusted sources. Consider using additional endpoint protection solutions that do not rely solely on Mark-of-the-Web tags for file trust decisions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2025-11-18T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 694184a13e7fd18214ba0e77
Added to database: 12/16/2025, 16:11:13 UTC
Last enriched: 07/05/2026, 21:05:39 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 251
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.