Improper Escaped Values in Lookyloo Web Interface Affects Domain Tree Rendering
CVE-2025-66460

5.3MEDIUM

Key Information:

Vendor

Lookyloo

Status
Vendor
CVE Published:
2 December 2025

What is CVE-2025-66460?

Lookyloo is a web interface enabling users to capture websites and visualize domain interactions. Before version 1.35.3, it was found to pass improperly escaped values to data table cells, particularly in the orthogonal-data feature. This flaw raises concerns about potential exploitation, especially in the popup view and likely across other parts of the interface. Users are strongly advised to upgrade to version 1.35.3 for patching this security issue.

Affected Version(s)

lookyloo < 1.35.3

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.