PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-11859 Thinkst Applied Research CVE debrief

CVE-2026-11859 is an HTML injection vulnerability in the 'fetch links' email sent by Thinkst Applied Research Canarytokens. This issue enables Interface Manipulation and Cross-Site Scripting (XSS) in email clients that render HTML emails. The vulnerability affects Canarytokens from Docker tag sha-c0f3cf142 before sha-08c3f93d and from Git commit c0f3cf142 before 08c3f93d. The CVSS score for this vulnerability is 2, with a severity rating of LOW.

Vendor
Thinkst Applied Research
Product
Canarytokens
CVSS
LOW 2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-10
Original CVE updated
2026-06-10
Advisory published
2026-06-10
Advisory updated
2026-06-10

Who should care

Users of Thinkst Applied Research Canarytokens, particularly those who use email clients that render HTML emails, should be aware of this vulnerability. This vulnerability could potentially allow attackers to manipulate the interface and execute Cross-Site Scripting (XSS) attacks.

Technical summary

The vulnerability is caused by an HTML injection issue in the 'fetch links' email sent by Canarytokens. This allows an attacker to inject malicious HTML code, potentially leading to Interface Manipulation and Cross-Site Scripting (XSS) attacks in vulnerable email clients.

Defensive priority

LOW

Recommended defensive actions

  • Update Canarytokens to the latest version (Docker tag sha-08c3f93d or later, or Git commit 08c3f93d or later) to fix the vulnerability.
  • Use email clients that do not render HTML emails or have strict security settings for rendering HTML content.

Evidence notes

The CVE record for CVE-2026-11859 can be found at [cve-org]. More details about the vulnerability are available at [ref-4], which includes information about the affected versions and the fix.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-11859 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-11859

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-11859 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-11859

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/thinkst/canarytokens/security/advisories/GHSA-55jf-cqr9-r7p4

    0f2be0ad-3469-4e56-b38f-4eb96719b425

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.