PT-2025-48752 · Lookyloo · Lookyloo

Published

2025-12-02

·

Updated

2025-12-05

·

CVE-2025-66459

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Lookyloo versions prior to 1.35.3
Description Lookyloo is a web interface used to capture website pages and display a tree of domains that interact with each other. A cross-site scripting (XSS) issue can occur when a user submits URLs for capture, including one containing a HTML element that causes the capture to fail. The resulting error message, which includes the problematic URL, is then displayed without proper sanitization, leading to XSS. The issue is triggered when the error field is populated with the bad URL.
Recommendations Update Lookyloo to version 1.35.3 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-66459
GHSA-HVMH-J2JX-48WG

Affected Products

Lookyloo