Executive brief
RansomLook is a ransomware tracking and analysis platform that generates PDF reports of security analysis. An authenticated user could embed malicious file:// or http:// links in analysis documents that would be resolved during PDF generation with the server's privileges and network access. This could expose sensitive files, credentials, or enable server-side request forgery attacks against internal services.
Technical details
The vulnerability is a resource validation bypass in the PDF generation pipeline. RansomLook converts Markdown analysis documents to HTML and passes them to WeasyPrint for PDF rendering; prior to patching, WeasyPrint's default URL fetcher resolved all resource references without restriction. An authenticated attacker could inject crafted file:// references to read arbitrary files on the system or http:// references to perform SSRF attacks against localhost or internal networks, exploiting the server's network context and file permissions. The fix implements a custom WeasyPrint URL fetcher that whitelists only data: URIs, report logos, and files within the analysis asset directory, rejecting all other network and filesystem access.
Affected products
- RansomLook RansomLook
Timeline
- 2026-08-24: disclosed