VYPR
High severity7.5NVD Advisory· Published Apr 21, 2026· Updated Jun 17, 2026

CVE-2026-40584

CVE-2026-40584

Description

RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the affected application improperly filters private location entries in website/web/api/genericapi.py. Because the code removes elements from a list while iterating over it, entries marked as private may be unintentionally retained in API responses, allowing unauthorized disclosure of non-public location information. This vulnerability is fixed in 1.9.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:ransomlook:ransomlook:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ransomlook:ransomlook:*:*:*:*:*:*:*:*range: <1.9.0
    • (no CPE)range: <1.9.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.