CVE-2026-13140: Thinkst Applied Research Canarytokens

Low severity, CVSS 1.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exploitation requires knowledge of a random identifier. This issue affects Canarytokens: from Docker tag sha-4116b92cb before sha-f5aa5c4e, from Git commit 4116b92cb before f5aa5c4e.

Affected products

Published 2026-06-24. Last modified 2026-06-25.