PT-2026-31667 · Loris · Loris

CVE-2026-39985

·

Published

2026-04-09

·

Updated

2026-04-09

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions LORIS versions prior to 27.0.3 LORIS versions prior to 28.0.1
Description LORIS is a self-hosted web application for neuroimaging research data and project management. The application fails to validate the value of the redirect parameter during the login process, allowing it to point to external locations. An attacker could use this to trick users into visiting arbitrary URLs by providing a link containing a third-party redirect parameter.
Recommendations Update to version 27.0.3. Update to version 28.0.1.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39985
GHSA-RCH2-F5FW-CG95

Affected Products

Loris