news.mlab.sh
1 result
vulnerability

OHIF Viewers DICOM

This advisory details a vulnerability in the OHIF Viewers DICOM framework, specifically versions up to v3.12.0, that allows attackers to steal authenticated user tokens via crafted links. The vulnerability stems from unchecked URL parameters within the DICOMWebProxy and DICOMJSON data sources, which inject the user's O…

CISA Advisories · Jun 25, 2026 High