<Vulnerability name="CVE-2026-13324">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-06-25T10:07:00</PublicDate>
    <Bugzilla id="2492860" url="https://bugzilla.redhat.com/show_bug.cgi?id=2492860" xml:lang="en:us">
geary: geary: Silent file attachment via ?attach= parameter
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>6.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</CVSS3ScoringVector>
    </CVSS3>
    <Details xml:lang="en:us" source="Red Hat">
A vulnerability has been identified in the **GNOME Geary** package within its **`mailto` URI handling** component. This flaw occurs because the email client automatically processes a non-standard `attach` parameter in email links without prompting or alerting the user.

An attacker could exploit this by tricking a user into clicking a specially crafted link (for example, `mailto:user@example.com?attach=/path/to/sensitive_file`). When clicked, Geary will automatically open a new compose window with the specified local file already attached. Because there is no dialog box or visual warning indicating that the file was attached by the link rather than the user, the user might unknowingly send sensitive files or data to the attacker upon hitting send.
    </Details>
    <Statement xml:lang="en:us">
- This issue is classified as Moderate severity primarily.
- Conditions for Exploitation: Exploitation requires significant user interaction, as a victim must be tricked into manually sending the email without noticing the unexpectedly attached file.

- Impact Limitations: The vulnerability is strictly limited to targeted information disclosure, and does not allow for remote code execution, broader system compromise, or privilege escalation.
    </Statement>
    <Mitigation xml:lang="en:us">
To mitigate this risk, avoid clicking untrusted `mailto` links and always review all attachments before sending an email. 

Alternatively, you can configure a different email client as your default `mailto` handler to disable Geary's automatic attachment functionality.
    </Mitigation>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-13324
https://nvd.nist.gov/vuln/detail/CVE-2026-13324
https://gitlab.gnome.org/GNOME/geary/-/work_items/1704
    </References>
</Vulnerability>