PT-2025-48751 · Lookyloo · Lookyloo
Published
2025-12-02
·
Updated
2025-12-05
·
CVE-2025-66458
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Lookyloo versions prior to 1.35.3
Description
Lookyloo is a web interface used to capture website pages and display a tree of domains that interact with each other. Prior to version 1.35.3, multiple Cross-Site Scripting (XSS) issues exist due to the unsafe use of f-strings in Markup. Exploitation requires a malicious third-party server responding with a JSON document containing JavaScript code within a script element.
Recommendations
Update to version 1.35.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lookyloo