CVE-2026-12888 PUBLISHED

HTML injection in the Canarytoken Google Chat notification

Assigner: ThinkstAppliedResearch
Reserved: 22.06.2026 Published: 22.06.2026 Updated: 22.06.2026

An HTML injection vulnerability exists in the Google Chat webhook notification  sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation in Google Chat. An attacker can insert limited HTML content including links.

This issue affects Canarytokens: from Docker tag sha-4aef1db90 before sha-8ab4dccd, from Git commit 4aef1db90 before 8ab4dccd.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:P/AU:N/RE:L/U:Green
CVSS Score: 2

Product Status

Vendor Thinkst Applied Research
Product Canarytokens
Versions Default: unaffected
  • affected from sha-4aef1db90 to sha-8ab4dccd (excl.)
  • affected from 4aef1db90 to 8ab4dccd (excl.)

Solutions

Pull the latest Docker image:

$ docker pull thinkst/canarytokens:latest

Credits

  • GitHub.com/geo-chen finder

References

Problem Types

  • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE

Impacts

  • CAPEC-113 Interface Manipulation