CVE-2026-34392

HIGH

LORIS has a path traversal in static router

Title source: cna
STIX 2.1

Description

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 and 28.0.1, a bug in the static file router can allow an attacker to traverse outside of the intended directory, allowing unintended files to be downloaded through the static, css, and js endpoints. This vulnerability is fixed in 27.0.3 and 28.0.1.

Scores

CVSS v3 7.5
EPSS 0.0004
EPSS Percentile 12.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-552
Status published
Products (4)
aces/Loris >= 20.0.0, < 27.0.3
aces/Loris >= 28.0.0, < 28.0.1
mcgill/loris 28.0.0
mcgill/loris 20.0.0 - 27.0.3
Published Apr 08, 2026
Tracked Since Apr 09, 2026