Privacy Enforcement Flaw in RansomLook Exposing Victim Data
CVE-2026-78380
What is CVE-2026-78380?
RansomLook contains a privacy enforcement flaw that fails to properly restrict the distribution of victim information associated with private ransomware groups and markets. Due to insufficient verification of group and market privacy settings, victim posts marked as private can be disseminated via public notification channels such as Rocket.Chat, Mastodon, Bluesky, and email, as well as being included in the public MISP feed. This unintentional exposure could lead to unauthorized access to sensitive information regarding ransomware incidents, compromising victim anonymity and security. The introduced fix implements a validation check for both groups and markets, ensuring that private posts are not forwarded to external channels or the public MISP feed, while maintaining internal data security and alerting capabilities.
Affected Version(s)
ransomlook 0 <= 2.0.0
