Redis Glob Pattern Injection Vulnerability in Ransomlook
CVE-2026-78378

6.9MEDIUM

Key Information:

Vendor

Ransomlook

Vendor
CVE Published:
24 August 2026

What is CVE-2026-78378?

Ransomlook contains a vulnerability that allows attackers to inject Redis glob patterns due to a lack of proper sanitization of user inputs. This issue arises when the /api/health/ endpoint resorts to using attacker-supplied values in Redis key patterns if the resolution fails. By exploiting this, unauthenticated attackers can use specific characters like *, ?, [, or ] to manipulate SCAN operations, potentially exposing sensitive health information across all groups, including private entities. Additionally, similar vulnerabilities exist in other API endpoints, increasing the risk of unauthorized access and data leakage. The remediation involves escaping user-controlled inputs before they are processed in Redis SCAN MATCH expressions.

Affected Version(s)

ransomlook 0 <= 2.0.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
Fafner [_KeyZee_]
.