Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2026-40584— RansomLook - Improper Filtering of Private Location Entries in API Endpoints Leads to Information Exposure

EPSS 0.04% · P13
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-40584

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RansomLook - Improper Filtering of Private Location Entries in API Endpoints Leads to Information Exposure
Source: NVD (National Vulnerability Database)
Vulnerability Description
RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the affected application improperly filters private location entries in website/web/api/genericapi.py. Because the code removes elements from a list while iterating over it, entries marked as private may be unintentionally retained in API responses, allowing unauthorized disclosure of non-public location information. This vulnerability is fixed in 1.9.0.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
信息暴露
Source: NVD (National Vulnerability Database)
Vulnerability Title
RansomLook 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
RansomLook是RansomLook开源的一个勒索软件团伙与市场监控工具。 RansomLook 1.9.0之前版本存在信息泄露漏洞,该漏洞源于受影响应用程序中的API在website/web/api/genericapi.py中不当过滤私有位置条目,可能导致在迭代列表时删除元素,无意中在API响应中保留标记为私有的条目,从而未经授权披露非公开位置信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
RansomLookRansomLook < 1.9.0 -

II. Public POCs for CVE-2026-40584

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-40584

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2026-40584

No comments yet


Leave a comment