Junglewise Threat Intelligence

CVE-2026-78381: RansomLook path traversal in GroupPost.get API

CVE-2026-78381 · Severity: info · Published 2026-08-24

Technologies: RansomLook.

Executive brief

RansomLook is a web application that manages group posts, including the ability to import post data from remote instances. A path traversal vulnerability in the GroupPost.get API allows attackers with administrative privileges to read arbitrary files from the server by crafting malicious post data. An attacker could expose sensitive configuration files, API credentials, or password hashes stored on the affected system.

Technical details

RansomLook's GroupPost.get API handler concatenates a database-controlled screen field value directly with the application's source/ directory and opens the resulting file without path validation. The screen field is free-form and can be populated through the administrative editor or imported from a remote RansomLook instance. An attacker controlling upstream instance data can inject path traversal sequences (e.g., ../config/generic.json) that, when the post is retrieved via API, cause the application to read and return the file contents Base64-encoded. The vulnerability requires administrative privileges but can be exploited through data imported from a malicious upstream instance without requiring an account on the target. The fix validates resolved paths using os.path.realpath() to ensure they remain within the source/ directory, applied both at write and read time, preventing symbolic link traversal attacks.

Affected products

  • RansomLook <UNKNOWN>

Timeline

  • 2026-08-24: disclosed