Junglewise Threat Intelligence

CVE-2026-13140: Thinkst Canarytokens stored XSS in AWS API key store

CVE-2026-13140 · Severity: info · CVSS 2 · Published 2026-06-24

Technologies: Thinkst Applied Research Canarytokens. Vendors: Thinkst Applied Research.

Executive brief

Thinkst Canarytokens is a security tool used to create 'honeytokens' that alert administrators when unauthorized users interact with them. A security flaw in the AWS API key store component could allow an attacker to execute malicious scripts in a user's browser if they click a specific link. While the impact is limited because the service does not use traditional user sessions, an attacker could potentially extract details about specific targeted security tokens.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the 'public_location' field of the AWS API key store in Thinkst Canarytokens. The root cause is improper neutralization of input during web page generation, where the affected field is rendered in the UI without sufficient sanitization. To exploit this, an attacker requires knowledge of a random, unguessable identifier and must convince a victim to click a rendered link. Successful exploitation allows the execution of JavaScript in the victim's browser within the canarytokens.org domain, though impact is limited to extracting details about the targeted AWS API Key Canarytoken as the site does not utilize user sessions. The issue is patched in Docker tag sha-f5aa5c4e and Git commit f5aa5c4e.

Affected products

  • Thinkst Applied Research Canarytokens Docker tag sha-4116b92cb before sha-f5aa5c4e, Git commit 4116b92cb before f5aa5c4e

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: advisory
  • 2026-06-24: patched

References

Related threats