PT-2026-31667 · Loris · Loris
CVE-2026-39985
·
Published
2026-04-09
·
Updated
2026-04-09
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LORIS versions prior to 27.0.3
LORIS versions prior to 28.0.1
Description
LORIS is a self-hosted web application for neuroimaging research data and project management. The application fails to validate the value of the redirect parameter during the login process, allowing it to point to external locations. An attacker could use this to trick users into visiting arbitrary URLs by providing a link containing a third-party redirect parameter.
Recommendations
Update to version 27.0.3.
Update to version 28.0.1.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Loris