CVE-2026-78385: RansomLook Analysis PDF Generation Allows Server-Side Request Forgery and Arbitrary Local File Access
RansomLook contains insufficient resource validation in the analysis PDF generation functionality. Analysis documents are converted from Markdown to HTML and passed to WeasyPrint for PDF rendering. Prior to the fix, WeasyPrint used its default URL fetcher, allowing resource references contained in an analysis to be resolved without restrictions.
An authenticated attacker able to create or modify an analysis could embed crafted resource references using schemes such as file:// or http://. When the analysis was subsequently rendered as PDF, WeasyPrint would process these references with the privileges and network access of the RansomLook server.
A malicious file:// reference could cause the renderer to access arbitrary files readable by the RansomLook process, potentially exposing sensitive configuration, credentials, or other local data through rendered resources. Network URLs could cause the server to initiate requests to localhost, internal network services, or external systems, resulting in server-side request forgery (SSRF) and potentially bypassing network-level access restrictions.
The patch introduces a dedicated WeasyPrint URL fetcher that permits only data: resources, the RansomLook report logo, and files contained within the analysis asset directory. Network resources and filesystem paths outside these explicitly permitted locations are rejected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Use the dedicated WeasyPrint URL fetcher for analysis PDF rendering and restrict resource references to only data: resources, the RansomLook report logo, and filesystem files contained within the analysis asset directory; reject all other network URLs and filesystem paths.
WeasyPrint URL fetcher in RansomLook Analysis PDF generation Allowed URL schemes/resources = data: resources, RansomLook report logo, and files within the analysis asset directory only
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated and able to create or modify an analysis. Exploitation occurs when that analysis is later rendered as a PDF.
Are installations using the default PDF-rendering behavior affected?
Yes. Before the fix, PDF rendering used WeasyPrint's default URL fetcher, which resolved resource references without the required restrictions.
What access does a successful exploit provide?
file:// references can cause the renderer to access files readable by the RansomLook process, potentially exposing configuration or credentials through rendered resources. Network URLs can make requests from the RansomLook server to localhost, internal services, or external systems.
What can be done if the fix cannot be deployed immediately?
Restrict the ability to create or modify analyses to trusted users and avoid rendering untrusted analyses as PDFs. The vulnerable behavior is triggered by resource references embedded in an analysis during PDF generation.