Junglewise Threat Intelligence

CVE-2026-78385: RansomLook insufficient resource validation in PDF generation

CVE-2026-78385 · Severity: info · CVSS 6.5 · Published 2026-08-24

Technologies: RansomLook. Vendors: RansomLook.

Executive brief

RansomLook is a ransomware tracking and analysis platform that generates PDF reports of security analysis. An authenticated user could embed malicious file:// or http:// links in analysis documents that would be resolved during PDF generation with the server's privileges and network access. This could expose sensitive files, credentials, or enable server-side request forgery attacks against internal services.

Technical details

The vulnerability is a resource validation bypass in the PDF generation pipeline. RansomLook converts Markdown analysis documents to HTML and passes them to WeasyPrint for PDF rendering; prior to patching, WeasyPrint's default URL fetcher resolved all resource references without restriction. An authenticated attacker could inject crafted file:// references to read arbitrary files on the system or http:// references to perform SSRF attacks against localhost or internal networks, exploiting the server's network context and file permissions. The fix implements a custom WeasyPrint URL fetcher that whitelists only data: URIs, report logos, and files within the analysis asset directory, rejecting all other network and filesystem access.

Affected products

  • RansomLook RansomLook

Timeline

  • 2026-08-24: disclosed

References

Related threats