High severity7.5NVD Advisory· Published Apr 21, 2026· Updated Apr 27, 2026
CVE-2026-40584
CVE-2026-40584
Description
RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the affected application improperly filters private location entries in website/web/api/genericapi.py. Because the code removes elements from a list while iterating over it, entries marked as private may be unintentionally retained in API responses, allowing unauthorized disclosure of non-public location information. This vulnerability is fixed in 1.9.0.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/RansomLook/RansomLook/security/advisories/GHSA-hv66-vcqc-v87cnvdVendor Advisory
- vulnerability.circl.lu/vuln/gcve-1-2026-0025nvdThird Party Advisory
News mentions
0No linked articles in our index yet.