Junglewise Threat Intelligence

CVE-2026-12888: Thinkst Canarytokens HTML injection in Google Chat notifications

CVE-2026-12888 · Severity: info · CVSS 0 · Published 2026-06-22

Technologies: Thinkst Applied Research Canarytokens. Vendors: Thinkst Applied Research.

Executive brief

Thinkst Canarytokens is a tool used to create 'honeytokens' that alert security teams when an intruder interacts with them. A vulnerability in the Google Chat notification system allowed attackers to inject custom HTML content, such as links and images, into the alerts sent to security teams. While this does not allow for full system takeover, it could be used to mislead security responders or conduct phishing attacks within the internal chat environment.

Technical details

An HTML injection vulnerability exists in the Google Chat notification component of Thinkst Canarytokens. The root cause is the failure to escape certain fields, specifically the User-Agent and Referer headers, before they are transmitted via the Google Chat webhook. A remote, unauthenticated attacker can trigger a canarytoken with malicious header values to inject limited HTML elements, such as links and images, into the resulting Google Chat notification. This allows for interface manipulation and potential phishing within the chat session. The issue is patched in Docker images and Git commits following sha-8ab4dccd.

Affected products

  • Thinkst Applied Research Canarytokens Docker tag sha-4aef1db90 before sha-8ab4dccd; Git commit 4aef1db90 before 8ab4dccd

Timeline

  • 2026-06-22: disclosed
  • 2026-06-22: advisory
  • 2026-06-22: patched

References

Related threats