CVE-2026-35169 is a reflected cross-site scripting vulnerability in the help_editor module of LORIS (Longitudinal Online Research and Imaging System), a self-hosted web application used for neuroimaging research data and project management. The flaw stems from improper sanitization of user-supplied variables in versions prior to 27.0.3 and 28.0.1. The same input vector also permits unauthorized download of arbitrary markdown files from affected servers. The vulnerability has a CVSS v3.1 score of 5.4 (Medium severity) with network-based attack vector and low attack complexity, but requires user interaction and authenticated access. The attack has limited impact, affecting confidentiality and integrity but not availability. The vulnerability represents a moderate risk requiring low privileges and social engineering to exploit through a malicious link. There is no evidence of active exploitation. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and is not featured on the Hot List, indicating minimal community attention and no publicly available exploit code. The EPSS score of 0.00033 suggests very low probability of exploitation in the wild. Organizations running LORIS should prioritize patching to versions 27.0.3 or 28.0.1 as part of routine maintenance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.10, <= 27.0.2CPE matchmatch criteria | cpe:2.3:a:mcgill:loris:*:*:*:*:*:*:*:* | ||
28.0.0CPE matchmatch criteria | cpe:2.3:a:mcgill:loris:28.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.