An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails. This issue affects Canarytokens: from Docker tag sha-c42435e before sha-bfda4df, from Git commit c42435e before bfda4df.
History

Fri, 05 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Thinkst Applied Research
Thinkst Applied Research canarytokens
Vendors & Products Thinkst Applied Research
Thinkst Applied Research canarytokens

Wed, 03 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 14:15:00 +0000

Type Values Removed Values Added
Description An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails. This issue affects Canarytokens: from Docker tag sha-c42435e before sha-bfda4df, from Git commit c42435e before bfda4df.
Title HTML injection in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens
Weaknesses CWE-74
References
Metrics cvssV4_0

{'score': 1.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:P/AU:N/RE:L/U:Green'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ThinkstAppliedResearch

Published: 2026-06-03T13:02:15.195Z

Updated: 2026-06-03T15:44:50.812Z

Reserved: 2026-06-03T10:21:12.713Z

Link: CVE-2026-10729

cve-icon Vulnrichment

Updated: 2026-06-03T15:44:47.969Z

cve-icon NVD

Status : Deferred

Published: 2026-06-03T14:16:35.533

Modified: 2026-06-04T16:37:27.810

Link: CVE-2026-10729

cve-icon Redhat

No data.