PT-2026-31426 · Loris · Loris
Published
2026-04-08
·
Updated
2026-04-09
·
CVE-2026-35165
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LORIS versions 21.0.0 through 27.0.2 and 28.0.0
Description
LORIS is a self-hosted web application for neuroimaging research data and project management. A flaw exists where the backend endpoint did not properly verify file access permissions while the frontend was restricting access. This could allow a user to download files they are not authorized to access if they know or can determine the filename.
Recommendations
Update to version 27.0.3 or 28.0.1
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Loris