Sensitive Information Exposure in RansomLook Product by RansomLook
CVE-2026-78386
8.7HIGH
What is CVE-2026-78386?
RansomLook has a vulnerability where sensitive configurations related to operator-side scraping are exposed through unauthenticated API responses. When queried by unauthorized users, these responses could reveal vital information such as authentication headers, session cookies, or credentials used for monitoring. Such exposure allows potential attackers to replicate these credentials against monitored services, undermining the entire scraping protection mechanism. As a mitigation measure, RansomLook has implemented an allowlist of fields for public location records, ensuring that sensitive internal data is not disclosed to unauthenticated callers.
Affected Version(s)
ransomlook 0 <= 2.0.0
