Executive brief
Lookyloo, a tool used for analyzing and visualizing web captures, is vulnerable to a security flaw in its visualization page. An attacker can craft malicious web content that, when captured and viewed by a user, executes unauthorized code in that user's browser. This could allow the attacker to steal sensitive information, hijack the user's session, or modify data within the application.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Lookyloo capture tree visualization page. The root cause is the insecure embedding of serialized capture tree data directly into an inline JavaScript block using the Jinja 'safe' filter, which bypasses automatic escaping. Because this data can contain attacker-controlled content from captured web pages, a malicious payload can terminate the <script> block and inject arbitrary HTML or JavaScript. An attacker can exploit this to perform actions on behalf of an authenticated user or access sensitive session information. The vulnerability is fixed in versions following 1.40.0 by moving the data to a dedicated API endpoint and processing it via response.json() on the client side.
Affected products
- Lookyloo Lookyloo <= 1.40.0
Timeline
- 2026-07-21: patched: Fix committed to GitHub repository.
- 2026-07-27: advisory: CVE published to NVD.