This issue affects Canarytokens: from Docker tag sha-c0f3cf142 before sha-08c3f93d, from Git commit c0f3cf142 before 08c3f93d.
No advisories yet.
Solution
Pull the latest Docker image: $ docker pull thinkst/canarytokens:latest
Workaround
No workaround given by the vendor.
Wed, 10 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thinkst Applied Research
Thinkst Applied Research canarytokens |
|
| Vendors & Products |
Thinkst Applied Research
Thinkst Applied Research canarytokens |
Wed, 10 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails. This issue affects Canarytokens: from Docker tag sha-c0f3cf142 before sha-08c3f93d, from Git commit c0f3cf142 before 08c3f93d. | |
| Title | HTML injection in the Canarytoken links email | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ThinkstAppliedResearch
Published:
Updated: 2026-06-10T14:38:21.778Z
Reserved: 2026-06-10T10:35:44.979Z
Link: CVE-2026-11859
Updated: 2026-06-10T14:36:45.569Z
Status : Received
Published: 2026-06-10T12:16:25.067
Modified: 2026-06-10T12:16:25.067
Link: CVE-2026-11859
No data.
OpenCVE Enrichment
Updated: 2026-06-10T15:00:13Z