CVE-2017-1000485: Nylas Mail Lives Project Nylas Mail
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Nylas Mail Lives 2.2.2 uses 0755 permissions for $HOME/.nylas-mail, which allows local users to obtain sensitive authentication information via standard filesystem operations.
Affected products
- Nylas Mail Lives Project Nylas Mail: version 2.2.2 only
Published 2018-01-03. Last modified 2026-06-17.