Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40584

25
FAUCET Score

CVE-2026-40584 affects RansomLook versions prior to 1.9.0, a tool designed to monitor ransomware groups and their victim markets. The vulnerability exists in the application's API within the genericapi.py file, where improper filtering of private location entries allows unauthorized disclosure of non-public location data. This occurs because the code removes elements from a list while iterating over it, causing some entries marked as private to be unintentionally retained in API responses. The vulnerability presents a moderate risk with a FAUCET Risk Score of 46.0 out of 100. While specific CVSS metrics are not available, the issue fundamentally represents an information disclosure vulnerability with potential network-based access, though exploitation would require knowledge of the API structure and authenticated or direct API access capabilities. The vulnerability is not currently being actively exploited in the wild, as evidenced by its absence from the Known Exploited Vulnerabilities catalog and its inactive status on public threat tracking lists. The EPSS score of 0.00042 indicates minimal likelihood of exploitation in the near term. However, organizations running RansomLook should prioritize upgrading to version 1.9.0 to prevent potential exposure of sensitive location information related to ransomware victims.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.9.0CPE matchmatch criteria
cpe:2.3:a:ransomlook:ransomlook:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
19.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 4th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / RansomLook/RansomLook/security/advisories/GHSA-hv66-vcqc-v87c
Vendor Advisory
vulnerability.circl.lu / vuln/gcve-1-2026-0025
Third Party Advisory