Executive brief
Orthanc Explorer 2, a web interface for the Orthanc DICOM server used in medical imaging, is vulnerable to a cross-site scripting (XSS) attack. An attacker can craft a malicious link that, when clicked by a user, executes unauthorized code in their browser. This could allow an attacker to perform actions on behalf of the user or access sensitive medical data within the application.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Orthanc Explorer 2 up to version 1.12.0. The 'remote-source' URL query parameter is retrieved from the route without sanitization and stored in the 'remoteSource' variable within 'WebApplication/src/components/StudyList.vue'. This variable is subsequently rendered using the 'v-html' directive through a vue-i18n translation string. Because the 'escapeParameter' setting was not enabled in the i18n configuration, raw HTML input is executed by the browser. An attacker can exploit this by tricking a user into clicking a specially crafted URL. A patch has been identified (commit 21f78ce) which upgrades the i18n library and addresses the sanitization issue.
Affected products
- Orthanc Orthanc Explorer 2 up to 1.12.0
Timeline
- 2026-04-26: disclosed: Issue reported on GitHub
- 2026-05-05: patched: Fix committed to repository
- 2026-05-31: advisory: CVE published