Reflected Cross-Site Scripting and File Download Vulnerability in LORIS by ACES
CVE-2026-35169
8.7HIGH
What is CVE-2026-35169?
The LORIS application, a self-hosted web solution for neuroimaging research, has a vulnerability in its help_editor module that improperly sanitizes user-supplied input. This oversight can lead to reflected cross-site scripting attacks, where a user may be tricked into clicking on a malicious link. Additionally, this same vulnerability can enable attackers to download arbitrary markdown files from an unpatched server. Users are advised to update to versions 27.0.3 and 28.0.1 to mitigate these risks.
Affected Version(s)
Loris >= , < 27.0.3 < , 27.0.3
Loris >= 28.0.0, < 28.0.1 < 28.0.0, 28.0.1
