HTML Injection Vulnerability in Thinkst Applied Research Canarytokens
CVE-2026-10729
1.2LOW
What is CVE-2026-10729?
An HTML injection vulnerability exists in the notification email functionality for the 'Slow Redirect' and 'Cloned Website' features in Thinkst Applied Research's Canarytokens. This flaw allows for interface manipulation and potential cross-site scripting (XSS) attacks when HTML emails are rendered by affected email clients. This issue impacts specific Docker tags and Git commits of the Canarytokens product, emphasizing the need for users to review and update their installations promptly to mitigate risks associated with this vulnerability.
Affected Version(s)
Canarytokens sha-c42435e
Canarytokens c42435e
