CVE-2026-13140
Stored Cross-Site Scripting in Canarytokens.org
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exploitation requires knowledge of a random identifier. This issue affects Canarytokens: from Docker tag sha-4116b92cb before sha-f5aa5c4e, from Git commit 4116b92cb before f5aa5c4e.
| CWE | CWE-79 |
| Vendor | thinkst applied research |
| Product | canarytokens |
| Published | Jun 24, 2026 |
| Last Updated | Jun 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for thinkst applied research canarytokens
Be the first to know when new unknown vulnerabilities affecting thinkst applied research canarytokens are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Thinkst Applied Research / Canarytokens
sha-4116b92cb < f5aa5c4e 4116b92cb < f5aa5c4e
References
Credits
Arkadiusz Marta