OVERVIEW CVE-2026-39985 is an open redirect vulnerability affecting LORIS (Longitudinal Online Research and Imaging System), a self-hosted web application used for neuroimaging research data and project management. The vulnerability exists in versions prior to 27.0.3 and 28.0.1, where the redirect parameter during user login fails to validate that redirected URLs remain within the LORIS application. This omission allows attackers to craft malicious links containing third-party redirect parameters that could trick users into visiting arbitrary external websites. SEVERITY The vulnerability carries a CVSS score of 6.1 (Medium) with a network-based attack vector that requires minimal complexity and user interaction. The attack necessitates social engineering to convince users to click a malicious link, which reflects the MEDIUM rating. The impact is limited to low-level confidentiality and integrity compromise; there is no availability impact. This profile is consistent with open redirect vulnerabilities, where damage depends primarily on attacker creativity and user susceptibility rather than technical exploitation difficulty. EXPLOITATION STATUS There is no indication of active exploitation, with no known publicly available exploit code identified. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on industry hotlists. Community attention appears minimal, as reflected in the low EPSS score of 0.00034, indicating this threat ranks below the vast majority of documented vulnerabilities in real-world exploitation prevalence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 27.0.3CPE matchmatch criteria | cpe:2.3:a:mcgill:loris:*:*:*:*:*:*:*:* | ||
28.0.0CPE matchmatch criteria | cpe:2.3:a:mcgill:loris:28.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.