VYPR

Canarytokens

by Canarytokens

Source repositories

CVEs (5)

  • CVE-2024-41664MedJul 23, 2024
    risk 0.35cvss 5.4epss 0.00

    Canarytokens help track activity and actions on a network. Prior to `sha-8ea5315`, Canarytokens.org was vulnerable to a blind SSRF in the Webhook alert feature. When a Canarytoken is created, users choose to receive alerts either via email or via a webhook. If a webhook is…

  • CVE-2024-41663LowJul 23, 2024
    risk 0.23cvss 3.5epss 0.00

    Canarytokens help track activity and actions on a network. A Cross-Site Scripting vulnerability was identified in the "Cloned Website" Canarytoken, whereby the Canarytoken's creator can attack themselves. The creator of a slow-redirect Canarytoken can insert Javascript into the…

  • CVE-2026-28355LowFeb 27, 2026
    risk 0.08cvss epss 0.00

    Canarytokens help track activity and actions on a network. Versions prior to `sha-7ff0e12` have a Self Cross-Site Scripting vulnerability in the "PWA" Canarytoken, whereby the Canarytoken's creator can attack themselves or someone they share the link with. The creator of a PWA…

  • CVE-2024-28111MedMar 6, 2024
    risk 0.00cvss 6.5epss 0.01

    Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canarytoken's incidents in CSV format. The generation of these CSV files is vulnerable to a CSV Injection vulnerability. This flaw can be used by an attacker who…

  • CVE-2022-31113MedJul 1, 2022
    risk 0.00cvss 6.3epss 0.01

    Canarytokens is an open source tool which helps track activity and actions on your network. A Cross-Site Scripting vulnerability was identified in the history page of triggered Canarytokens. This permits an attacker who recognised an HTTP-based Canarytoken (a URL) to execute…