CVE-2026-10729 PUBLISHED

HTML injection in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens

Assigner: ThinkstAppliedResearch
Reserved: 03.06.2026 Published: 03.06.2026 Updated: 03.06.2026

An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails.

This issue affects Canarytokens: from Docker tag sha-c42435e before sha-bfda4df, from Git commit c42435e before bfda4df.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:P/AU:N/RE:L/U:Green
CVSS Score: 1.2

Product Status

Vendor Thinkst Applied Research
Product Canarytokens
Versions Default: unaffected
  • affected from sha-c42435e to sha-bfda4df (excl.)
  • affected from c42435e to bfda4df (excl.)

Solutions

Pull the latest Docker image:

$ docker pull thinkst/canarytokens:latest

Credits

  • Gaurav Popalghat finder

References

Problem Types

  • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE

Impacts

  • CAPEC-113 Interface Manipulation
  • CAPEC-63 Cross-Site Scripting (XSS)