CVE-2026-40584

RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the affected application improperly filters private location entries in website/web/api/genericapi.py. Because the code removes elements from a list while iterating over it, entries marked as private may be unintentionally retained in API responses, allowing unauthorized disclosure of non-public location information. This vulnerability is fixed in 1.9.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ransomlook:ransomlook:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-21 17:16

Updated : 2026-06-17 10:45


NVD link : CVE-2026-40584

Mitre link : CVE-2026-40584

CVE.ORG link : CVE-2026-40584


JSON object : View

Products Affected

ransomlook

  • ransomlook
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor