CVE-2026-40584: RansomLook - Improper Filtering of Private Location Entries in API Endpoints Leads to Information Exposure
RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the affected application improperly filters private location entries in website/web/api/genericapi.py. Because the code removes elements from a list while iterating over it, entries marked as private may be unintentionally retained in API responses, allowing unauthorized disclosure of non-public location information. This vulnerability is fixed in 1.9.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
affected application APIto a version that resolves this vulnerability.Fixed in 1.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40584?
CVE-2026-40584 has been classified as a medium severity vulnerability.
How do I fix CVE-2026-40584?
To fix CVE-2026-40584, upgrade RansomLook to version 1.9.0 or later.
What type of information is exposed due to CVE-2026-40584?
CVE-2026-40584 allows exposure of private location entries through API endpoints.
Which versions of RansomLook are affected by CVE-2026-40584?
RansomLook versions prior to 1.9.0 are affected by CVE-2026-40584.
Is CVE-2026-40584 related to Ransomware monitoring?
Yes, CVE-2026-40584 impacts RansomLook, a tool used for monitoring ransomware groups and markets.