CVE-2026-40584 affects RansomLook versions prior to 1.9.0, a tool designed to monitor ransomware groups and their victim markets. The vulnerability exists in the application's API within the genericapi.py file, where improper filtering of private location entries allows unauthorized disclosure of non-public location data. This occurs because the code removes elements from a list while iterating over it, causing some entries marked as private to be unintentionally retained in API responses. The vulnerability presents a moderate risk with a FAUCET Risk Score of 46.0 out of 100. While specific CVSS metrics are not available, the issue fundamentally represents an information disclosure vulnerability with potential network-based access, though exploitation would require knowledge of the API structure and authenticated or direct API access capabilities. The vulnerability is not currently being actively exploited in the wild, as evidenced by its absence from the Known Exploited Vulnerabilities catalog and its inactive status on public threat tracking lists. The EPSS score of 0.00042 indicates minimal likelihood of exploitation in the near term. However, organizations running RansomLook should prioritize upgrading to version 1.9.0 to prevent potential exposure of sensitive location information related to ransomware victims.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9.0CPE matchmatch criteria | cpe:2.3:a:ransomlook:ransomlook:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.