← Vulnerability feed

Vulnerability record · CVE-2026-39985 · published 9 April 2026

CVE-2026-39985: Mcgill loris open redirect vulnerability

Mcgill · Loris

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 28.0.1, the redirect parameter upon login to LORIS was not validating the value of the redirect as being within LORIS, which could be used to trick users into visiting arbitrary URLs if they are given a link with a third party redirect parameter. This vulnerability is fixed in 27.0.3 and 28.0.1.

6.1 CVSS 3.1 Medium EPSS 0.35% · top 74.2% CWE-601 · Open redirect
6.1CVSS 3.1 base score
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 28.0.1, the redirect parameter upon login to LORIS was not validating the value of the redirect as being within LORIS, which could be used to trick users into visiting arbitrary URLs if they are given a link with a third party redirect parameter. This vulnerability is fixed in 27.0.3 and 28.0.1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-39985 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-26984Mcgill loris path traversal vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 1.1%8.6CVE-2026-35446Mcgill loris vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.38%7.5CVE-2026-33350Mcgill loris sql injection vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.41%7.5CVE-2026-34392Mcgill loris vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.42%6.5CVE-2026-34985Mcgill loris insecure direct object reference vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.27%6.5CVE-2026-35165Mcgill loris insecure direct object reference vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.27%6.5CVE-2026-26985Mcgill loris path traversal vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.52%5.4CVE-2026-35169Mcgill loris cross-site scripting vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2026-39985), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.