KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7967.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "5.3.0" } ] } ]