🔐 CVE Alert

CVE-2026-13140

UNKNOWN 0.0

Stored Cross-Site Scripting in Canarytokens.org

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exploitation requires knowledge of a random identifier. This issue affects Canarytokens: from Docker tag sha-4116b92cb before sha-f5aa5c4e, from Git commit 4116b92cb before f5aa5c4e.

CWE CWE-79
Vendor thinkst applied research
Product canarytokens
Published Jun 24, 2026
Last Updated Jun 24, 2026
Stay Ahead of the Next One

Get instant alerts for thinkst applied research canarytokens

Be the first to know when new unknown vulnerabilities affecting thinkst applied research canarytokens are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Thinkst Applied Research / Canarytokens
sha-4116b92cb < f5aa5c4e 4116b92cb < f5aa5c4e

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/thinkst/canarytokens/security/advisories/GHSA-23pf-xjp2-48q6

Credits

Arkadiusz Marta