Junglewise Threat Intelligence

CVE-2026-10729: Thinkst Canarytokens HTML injection in notification emails

CVE-2026-10729 · Severity: info · CVSS 2.1 · Published 2026-06-03

Technologies: Thinkst Applied Research Canarytokens. Vendors: Thinkst Applied Research.

Executive brief

Thinkst Canarytokens is a tool used to create 'honeytokens' that alert administrators when an attacker interacts with them. A vulnerability in the "Slow Redirect" and "Cloned Website" token types allows an attacker to inject malicious HTML into the alert emails sent to administrators. This could be used to trick security staff into clicking phishing links or viewing unauthorized images within their email client during an investigation.

Technical details

An HTML injection vulnerability exists in the "Slow Redirect" and "Cloned Website" Canarytokens due to improper neutralization of the 'location' field. When these tokens are triggered, the unescaped 'location' data is included directly in the notification email sent to the user. An attacker can exploit this by providing malicious HTML in the location field, which may be rendered by the recipient's email client. While many modern email clients strip script tags, this flaw still enables interface manipulation, the insertion of phishing links, or the inclusion of external images. The issue is fixed in Docker images and Git commits following sha-bfda4df.

Affected products

  • Thinkst Applied Research Canarytokens Docker tags sha-c42435e before sha-bfda4df; Git commits c42435e before bfda4df

Timeline

  • 2026-06-03: disclosed
  • 2026-06-03: advisory
  • 2026-06-03: patched

References

Related threats