Improper Escaped Values in Lookyloo Web Interface Affects Domain Tree Rendering
CVE-2025-66460
5.3MEDIUM
What is CVE-2025-66460?
Lookyloo is a web interface enabling users to capture websites and visualize domain interactions. Before version 1.35.3, it was found to pass improperly escaped values to data table cells, particularly in the orthogonal-data feature. This flaw raises concerns about potential exploitation, especially in the popup view and likely across other parts of the interface. Users are strongly advised to upgrade to version 1.35.3 for patching this security issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
lookyloo < 1.35.3
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
