CVE 5.3 MEDIUM

Lookyloo vulnerable to XSS due to unescaped error message passed to innerHTML_CVE-2025-66459

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, a XSS vulnerability can be triggered when a user submits a list of URLs to capture, one of them contains a HTML element, and the capture fails. Then, the error field is populated with an error message that contains the bad URL they tried to capture, triggering the XSS. This vulnerability is fixed in 1.35.3.

Basic Information

ID CVE-2025-66459
Source GitHub_M
Published Dec 2, 2025 at 18:32
Modified Dec 2, 2025 at 19:28

Affected Product

Vendor Lookyloo
Product lookyloo
Version < 1.35.3
Affected Versions Lookyloo lookyloo < 1.35.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.