CVE-2026-10729

An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails. This issue affects Canarytokens: from Docker tag sha-c42435e before sha-bfda4df, from Git commit c42435e before bfda4df.
CVSS

No CVSS.

Configurations

No configuration.

History

22 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de inyección HTML en el correo electrónico de notificación para los Canarytokens de 'Redirección Lenta' y 'Sitio Web Clonado' existe en Thinkst Applied Research Canarytokens, lo que permite la manipulación de la interfaz, cross-site scripting (XSS) en clientes de correo electrónico que renderizan correos HTML. Este problema afecta a Canarytokens: desde la etiqueta de Docker sha-c42435e anterior a sha-bfda4df, desde el commit de Git c42435e anterior a bfda4df.

03 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-03 14:16

Updated : 2026-07-22 19:10


NVD link : CVE-2026-10729

Mitre link : CVE-2026-10729

CVE.ORG link : CVE-2026-10729


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')