A vulnerability described as problematic has been identified in Lookyloo up to 1.40.0. Affected by this issue is the function
response.json of the component Capture Tree Visualization. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-66824. It is possible to launch the attack remotely. No exploit is available.
It is advisable to implement a patch to correct this issue.