CVE-2019-9768: Thinkst Canarytokens

High severity, CVSS 7.5. EPSS: 11.7% chance of exploitation in the next 30 days.

Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it easier for attackers to estimate whether a Word document contains a token.

Affected products

  • Thinkst Canarytokens: up to and including 2019-03-01

Published 2019-03-14. Last modified 2026-06-17.