Junglewise Threat Intelligence

CVE-2026-35446: aces LORIS path traversal in FilesDownloadHandler

CVE-2026-35446 · Severity: high · CVSS 7.7 · Published 2026-04-08

Executive brief

LORIS, a web-based platform used by research institutions to manage neuroimaging data and projects, contains a security flaw in how it handles file downloads. An attacker with basic user access could exploit this flaw to bypass folder restrictions and download sensitive files from the server that they should not be able to see. This could lead to the unauthorized exposure of confidential research data or system configuration files.

Technical details

A path traversal vulnerability exists in LORIS versions 24.0.0 through 27.0.2 and 28.0.0. The flaw is caused by an incorrect order of operations in the FilesDownloadHandler component, specifically involving the sequence of URL decoding and path resolution. By providing a specially crafted filename parameter, an authenticated attacker can escape the designated download directories to access arbitrary files on the host system. The vulnerability affects multiple modules including the document repository and electrophysiology uploader. This issue is resolved in versions 27.0.3 and 28.0.1 by ensuring proper path resolution occurs after URL decoding.

Affected products

  • aces LORIS (Longitudinal Online Research and Imaging System) 24.0.0 to < 27.0.3, 28.0.0

Timeline

  • 2026-04-08: advisory: Vendor advisory published via GitHub
  • 2026-04-08: disclosed
  • 2026-04-08: patched

References