CVE-2026-78378 PUBLISHED

Redis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ransomlook Data

Assigner: CIRCL
Reserved: 24.08.2026 Published: 24.08.2026 Updated: 24.08.2026

Ransomlook contains a Redis glob pattern injection vulnerability caused by insufficient neutralization of user-controlled input before it is incorporated into Redis SCAN MATCH patterns.

The /api/health/<name> endpoint attempted to resolve the supplied name to a known group or market, but when resolution failed it fell back to using the attacker-controlled value directly in a Redis key pattern. An unauthenticated attacker could therefore supply Redis glob metacharacters such as , ?, [ or ] to broaden the SCAN operation beyond the intended group. For example, requesting /api/health/ could enumerate health information, mirror slugs, and uptime series belonging to all groups and markets, including entities marked as private.

Similar unsafe interpolation was present in /api/crypto/chain/<chain> and in the delete_manual_torrent() function. The latter represents a potentially destructive sink because a crafted infohash containing glob metacharacters could cause the scan to match torrent-health keys belonging to other torrents if attacker-controlled input can reach that function.

The patch removes the unsafe fallback from the health endpoint and introduces glob escaping for user-controlled values before they are incorporated into Redis SCAN MATCH expressions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor ransomlook
Product ransomlook
Versions Default: unaffected
  • affected from 0 to 2.0.0 (incl.)

Credits

  • Jeroen Pinoy finder
  • Fafner [_KeyZee_] remediation developer

References

Problem Types

  • CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE

Impacts

  • CAPEC-153 Input Data Manipulation