Description
An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails.


This issue affects Canarytokens: from Docker tag sha-c42435e before sha-bfda4df, from Git commit c42435e before bfda4df.
Published: 2026-06-03
Score: 1.2 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an HTML injection issue in the notification emails generated for "Slow Redirect" and "Cloned Website" Canarytokens. When the token is triggered, the system sends an HTML email that contains the token information. Malicious content can be injected into the email body, allowing the attacker to execute arbitrary JavaScript or manipulate the page displayed by any email client that processes HTML. This weakness, classified as CWE‑74, can lead to interface manipulation and cross‑site scripting attacks in the email client context, potentially compromising the confidentiality or integrity of the message and enabling phishing or credential theft.

Affected Systems

Only the Canarytokens product from Thinkst Applied Research is affected. The issue exists in Docker images built from the commit sha‑c42435e up through, but not including, sha‑bfda4df, and in any Git‑based deployment that incorporates the corresponding code range. Versions tagged earlier than sha‑bfda4df are vulnerable, while later revisions incorporate the fix.

Risk and Exploitability

The CVSS score of 1.2 indicates a low overall severity, but the lack of an EPSS value and absence from the CISA KEV catalog do not eliminate the risk of exploitation in environments where HTML email rendering is common. The vulnerability is exploitable by simply triggering a Canarytoken that sends the notification email; an attacker who receives the email can then exploit the injected content in their email client. Because the vector is client‑side, the impact is limited to recipients of the notification email rather than the server itself. Maintaining current images mitigates the risk.

Generated by OpenCVE AI on June 3, 2026 at 15:23 UTC.

Remediation

Vendor Solution

Pull the latest Docker image: $ docker pull thinkst/canarytokens:latest


OpenCVE Recommended Actions

  • Pull the latest Docker image for Canarytokens: `docker pull thinkst/canarytokens:latest`
  • Redeploy the Canarytokens service using the updated image to ensure the fix is applied
  • Replace any older Docker tags (e.g., sha‑c42435e) in your deployment scripts with the latest image
  • Review custom HTML content in notification templates and sanitize user inputs to protect against future injection flaws

Generated by OpenCVE AI on June 3, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 14:15:00 +0000

Type Values Removed Values Added
Description An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails. This issue affects Canarytokens: from Docker tag sha-c42435e before sha-bfda4df, from Git commit c42435e before bfda4df.
Title HTML injection in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens
Weaknesses CWE-74
References
Metrics cvssV4_0

{'score': 1.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:P/AU:N/RE:L/U:Green'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: ThinkstAppliedResearch

Published:

Updated: 2026-06-03T15:44:50.812Z

Reserved: 2026-06-03T10:21:12.713Z

Link: CVE-2026-10729

cve-icon Vulnrichment

Updated: 2026-06-03T15:44:47.969Z

cve-icon NVD

Status : Received

Published: 2026-06-03T14:16:35.533

Modified: 2026-06-03T14:16:35.533

Link: CVE-2026-10729

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T15:30:26Z

Weaknesses