CVE-2026-78555
- EPSS 0.36%
- Veröffentlicht 24.08.2026 19:38:50
- Zuletzt bearbeitet 26.08.2026 16:49:18
RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Although the interface displayed only a shortened representation of each key, the full token was embedded in hidden form fields used by t...
- EPSS 0.14%
- Veröffentlicht 24.08.2026 19:28:49
- Zuletzt bearbeitet 26.08.2026 16:49:18
RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key file was created using the process's default permissions and umask, resulting in permissions such as 0644 under a common 022 umask. C...
CVE-2026-78551
- EPSS 0.41%
- Veröffentlicht 24.08.2026 19:20:03
- Zuletzt bearbeitet 26.08.2026 16:49:18
RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to enumerate valid usernames, perform unrestricted password-guessing attacks, and potentially exhaust application worker resources. ...
CVE-2026-78391
- EPSS 0.26%
- Veröffentlicht 24.08.2026 14:13:20
- Zuletzt bearbeitet 26.08.2026 16:49:18
RansomLook contains a stored cross-site scripting (XSS) vulnerability in the cryptocurrency wallet detail view. Cryptocurrency addresses and blockchain names originating from external sources, including the public crowd-sourced ransomwhe.re feed, wer...
CVE-2026-78387
- EPSS 0.35%
- Veröffentlicht 24.08.2026 14:04:17
- Zuletzt bearbeitet 26.08.2026 16:49:18
RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config endpoint. The endpoint requires an authenticated session but does not perform an explicit privilege or administrator authorization c...
CVE-2026-78386
- EPSS 0.48%
- Veröffentlicht 24.08.2026 13:55:57
- Zuletzt bearbeitet 26.08.2026 16:49:18
RansomLook exposed sensitive operator-side scraping configuration through multiple unauthenticated API responses. Location records associated with ransomware groups and markets were returned largely verbatim to unauthenticated callers whenever the lo...
CVE-2026-78385
- EPSS 0.26%
- Veröffentlicht 24.08.2026 13:49:50
- Zuletzt bearbeitet 26.08.2026 16:49:18
RansomLook contains insufficient resource validation in the analysis PDF generation functionality. Analysis documents are converted from Markdown to HTML and passed to WeasyPrint for PDF rendering. Prior to the fix, WeasyPrint used its default URL fe...
CVE-2026-78381
- EPSS 0.39%
- Veröffentlicht 24.08.2026 13:32:55
- Zuletzt bearbeitet 26.08.2026 16:49:18
RansomLook contains a path traversal vulnerability in the handling of the screen field associated with group posts. The GroupPost.get API handler concatenates the database-controlled screen value directly with the application's source/ directory and ...
CVE-2026-78380
- EPSS 0.28%
- Veröffentlicht 24.08.2026 13:26:56
- Zuletzt bearbeitet 26.08.2026 16:49:18
RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim posts to external notification channels. The post-processing logic checks whether an individual post is marked private but does n...
CVE-2026-78378
- EPSS 0.28%
- Veröffentlicht 24.08.2026 13:19:02
- Zuletzt bearbeitet 26.08.2026 16:49:18
Ransomlook contains a Redis glob pattern injection vulnerability caused by insufficient neutralization of user-controlled input before it is incorporated into Redis SCAN MATCH patterns. The /api/health/<name> endpoint attempted to resolve the suppl...