Impact
RansomLook's PDF generation process converts Markdown into HTML and renders it with WeasyPrint. The former used the default URL fetcher, permitting arbitrary resource fetching when generating PDFs. An authenticated attacker can embed crafted ``file://`` or ``http://`` references in an analysis, causing the server to read local files or make outbound requests while rendering the PDF. This flaw can expose configuration and credential data and enable server‑side request forgery (SSRF).
Affected Systems
The vulnerability affects RansomLook RansomLook. No specific product versions are listed, so any deployment of RansomLook that has not applied the documented fix is vulnerable.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. Although no EPSS data is available, the lack of restriction on resource resolution creates a clear exploitation path for users who can modify analyses. The vulnerability is not listed in CISA's KEV catalog, but the impact on confidentiality and the potential for SSRF warrant prompt remediation.
OpenCVE Enrichment