HTML Injection Vulnerability in Thinkst Applied Research Canarytokens
CVE-2026-10729

1.2LOW

What is CVE-2026-10729?

An HTML injection vulnerability exists in the notification email functionality for the 'Slow Redirect' and 'Cloned Website' features in Thinkst Applied Research's Canarytokens. This flaw allows for interface manipulation and potential cross-site scripting (XSS) attacks when HTML emails are rendered by affected email clients. This issue impacts specific Docker tags and Git commits of the Canarytokens product, emphasizing the need for users to review and update their installations promptly to mitigate risks associated with this vulnerability.

Affected Version(s)

Canarytokens sha-c42435e

Canarytokens c42435e

References

CVSS V4

Score:
1.2
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gaurav Popalghat
.