CVE-2017-1000485: Nylas Mail Lives Project Nylas Mail

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Nylas Mail Lives 2.2.2 uses 0755 permissions for $HOME/.nylas-mail, which allows local users to obtain sensitive authentication information via standard filesystem operations.

Affected products

Published 2018-01-03. Last modified 2026-06-17.