
CVE-2026-12888 An HTML injection vulnerability exists in the Google Chat webhook notification sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation in Goog… https://www.cve.org/CVERecord?id=CVE-2026-12888
Post summary
The record announces CVE‑2026‑12888, identifying an HTML injection flaw in Google Chat webhook notifications from Thinkst Canarytokens that permits interface manipulation, but provides no PoC, exploit, or patch details.
