Executive brief
RansomLook exposed full API keys in the HTML source code of its administrative API keys page, despite displaying only shortened versions to users. An attacker with access to the page source, browser cache, or monitoring tools could recover complete API credentials and use them to access data and services the key was authorized for. This vulnerability affected authenticated administrators and could be exploited through various intermediaries that retain HTTP response bodies.
Technical details
RansomLook embedded complete API keys in hidden form fields on the /admin/apikeys authenticated page, even though the user interface displayed only truncated representations. The full tokens were exposed in the HTML source and could be recovered through client-side inspection, cached responses, debugging proxies, or monitoring systems. An attacker with a leaked API key could authenticate with the privileges assigned to that key, potentially gaining unauthorized access to private data. The fix replaces API keys with SHA-256-derived opaque handles in rendered pages, disclosing the full key only at creation time; administrative actions use the handles which are resolved server-side.
Affected products
- RansomLook RansomLook
Timeline
- 2026-08-24: disclosed
- 2026-08-24: patched: Patch available in commit b358dfa