Improper Escaped Values in Lookyloo Web Interface Affects Domain Tree Rendering
CVE-2025-66460
5.3MEDIUM
What is CVE-2025-66460?
Lookyloo is a web interface enabling users to capture websites and visualize domain interactions. Before version 1.35.3, it was found to pass improperly escaped values to data table cells, particularly in the orthogonal-data feature. This flaw raises concerns about potential exploitation, especially in the popup view and likely across other parts of the interface. Users are strongly advised to upgrade to version 1.35.3 for patching this security issue.
Affected Version(s)
lookyloo < 1.35.3
