Skip to finding
important · RCE — REDCap

A public REDCap survey hash can expose unauthenticated server-side code execution.

Affects

REDCap, self-hosted research-data capture and public-survey servers used by healthcare and academic institutions.

Public-survey passthrough routing can reach an unintended Data Import controller, where an attacker-controlled path or stream parameter enters code generation.

Detail and 1 source

Fixed releases exist, but the held evidence is the CNA record rather than an independent public reproducer.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 21, 2026