RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the affected application improperly filters private location entries in website/web/api/genericapi.py. Because the code removes elements from a list while iterating over it, entries marked as private may be unintentionally retained in API responses, allowing unauthorized disclosure of non-public location information. This vulnerability is fixed in 1.9.0.
References
| Link | Resource |
|---|---|
| https://github.com/RansomLook/RansomLook/security/advisories/GHSA-hv66-vcqc-v87c | Vendor Advisory |
| https://vulnerability.circl.lu/vuln/gcve-1-2026-0025 | Third Party Advisory |
Configurations
History
27 Apr 2026, 19:47
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Ransomlook ransomlook
Ransomlook |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CPE | cpe:2.3:a:ransomlook:ransomlook:*:*:*:*:*:*:*:* | |
| References | () https://github.com/RansomLook/RansomLook/security/advisories/GHSA-hv66-vcqc-v87c - Vendor Advisory | |
| References | () https://vulnerability.circl.lu/vuln/gcve-1-2026-0025 - Third Party Advisory |
21 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-21 17:16
Updated : 2026-04-27 19:47
NVD link : CVE-2026-40584
Mitre link : CVE-2026-40584
CVE.ORG link : CVE-2026-40584
JSON object : View
Products Affected
ransomlook
- ransomlook
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
