PT-2025-48751 · Lookyloo · Lookyloo

Published

2025-12-02

·

Updated

2025-12-05

·

CVE-2025-66458

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Lookyloo versions prior to 1.35.3
Description Lookyloo is a web interface used to capture website pages and display a tree of domains that interact with each other. Prior to version 1.35.3, multiple Cross-Site Scripting (XSS) issues exist due to the unsafe use of f-strings in Markup. Exploitation requires a malicious third-party server responding with a JSON document containing JavaScript code within a script element.
Recommendations Update to version 1.35.3 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-66458
GHSA-58H2-652V-GQ87

Affected Products

Lookyloo