Medium severity4.3NVD Advisory· Published Apr 9, 2026· Updated Apr 22, 2026
CVE-2026-39985
CVE-2026-39985
Description
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 28.0.1, the redirect parameter upon login to LORIS was not validating the value of the redirect as being within LORIS, which could be used to trick users into visiting arbitrary URLs if they are given a link with a third party redirect parameter. This vulnerability is fixed in 27.0.3 and 28.0.1.
Affected products
2Patches
1f57f54b42a07https://github.com/aces/Lorisvia nvd-ref
Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
4- github.com/aces/Loris/commit/f57f54b42a076bf53ba86e20d4dbf37f63538f58nvdPatch
- github.com/aces/Loris/security/advisories/GHSA-rch2-f5fw-cg95nvdVendor Advisory
- github.com/aces/Loris/releases/tag/v27.0.3nvdRelease Notes
- github.com/aces/Loris/releases/tag/v28.0.1nvdRelease Notes
News mentions
0No linked articles in our index yet.