An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails.
This issue affects Canarytokens: from Docker tag sha-c42435e before sha-bfda4df, from Git commit c42435e before bfda4df.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thinkst Applied Research
Thinkst Applied Research canarytokens |
|
| Vendors & Products |
Thinkst Applied Research
Thinkst Applied Research canarytokens |
Wed, 03 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails. This issue affects Canarytokens: from Docker tag sha-c42435e before sha-bfda4df, from Git commit c42435e before bfda4df. | |
| Title | HTML injection in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ThinkstAppliedResearch
Published: 2026-06-03T13:02:15.195Z
Updated: 2026-06-03T15:44:50.812Z
Reserved: 2026-06-03T10:21:12.713Z
Link: CVE-2026-10729
Updated: 2026-06-03T15:44:47.969Z
Status : Deferred
Published: 2026-06-03T14:16:35.533
Modified: 2026-06-04T16:37:27.810
Link: CVE-2026-10729
No data.