An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails.
This issue affects Canarytokens: from Docker tag sha-c0f3cf142 before sha-08c3f93d, from Git commit c0f3cf142 before 08c3f93d.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thinkst Applied Research
Thinkst Applied Research canarytokens |
|
| Vendors & Products |
Thinkst Applied Research
Thinkst Applied Research canarytokens |
Wed, 10 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails. This issue affects Canarytokens: from Docker tag sha-c0f3cf142 before sha-08c3f93d, from Git commit c0f3cf142 before 08c3f93d. | |
| Title | HTML injection in the Canarytoken links email | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ThinkstAppliedResearch
Published:
Updated: 2026-06-10T11:35:14.974Z
Reserved: 2026-06-10T10:35:44.979Z
Link: CVE-2026-11859
No data.
Status : Received
Published: 2026-06-10T12:16:25.067
Modified: 2026-06-10T12:16:25.067
Link: CVE-2026-11859
No data.
OpenCVE Enrichment
Updated: 2026-06-10T13:30:05Z