# CVE-2024-28111

## Summary

- **CVE ID:** CVE-2024-28111
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
- **CWE:** CWE-1236
- **Published:** Mar 6, 2024
- **Last Modified:** Mar 13, 2026

## Description

Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canarytoken's incidents in CSV format. The generation of these CSV files is vulnerable to a CSV Injection vulnerability. This flaw can be used by an attacker who discovers an HTTP-based Canarytoken to target the Canarytoken's owner, if the owner exports the incident history to CSV and opens in a reader application such as Microsoft Excel. The impact is that this issue could lead to code execution on the machine on which the CSV file is opened. Version sha-c595a1f8 contains a fix for this issue.

## Affected Products

- thinkst — canarytokens (< sha-c595a1f8)

## References

- [CNA](https://github.com/thinkst/canarytokens/security/advisories/GHSA-fqh6-v4qp-65fv)
- [CNA](https://github.com/thinkst/canarytokens/commit/c595a1f884b986da2ca05aa5bff9ae5f93c6a4aa)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.63%
- **EPSS Percentile:** 48.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._