CVE-2026-10729

An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails. This issue affects Canarytokens: from Docker tag sha-c42435e before sha-bfda4df, from Git commit c42435e before bfda4df.
CVSS

No CVSS.

Configurations

No configuration.

History

03 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-03 14:16

Updated : 2026-06-04 16:37


NVD link : CVE-2026-10729

Mitre link : CVE-2026-10729

CVE.ORG link : CVE-2026-10729


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')