Impact
RansomLook does not enforce the privacy status of the group or market when sending newly parsed victim posts to external channels. The post‑processing logic checks an individual post’s private flag but ignores the parent group or market’s privacy setting. Consequently, posts that belong to a private group or market can be distributed through enabled Rocket.Chat, Mastodon, Bluesky, e‑mail notification channels, and the public MISP feed, exposing victim names, ransomware activity, incident information, or other sensitive details that were intended to remain private.
Affected Systems
The vulnerability exists in the RansomLook RansomLook platform. Affected versions are not enumerated in the advisory, so any deployed instance of the software that has not been updated with the patch may be vulnerable.
Risk and Exploitability
With a CVSS score of 8.7, this issue represents a high‑severity privacy breach. The exploitability score is not available, but the vulnerability can be abused by anyone who can observe the public notification channels or the public MISP feed; no direct access to the RansomLook system is required. Those who have such access may obtain victim information that should have been protected. The knock‑on effect is disclosure of personal or business data, potentially leading to reputational loss or targeted attacks against affected victims.
OpenCVE Enrichment