PatchSiren

immich-app CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL immich-app CVE published 2026-06-23

CVE-2026-53662

CVE-2026-53662 is a critical vulnerability in Immich, a self-hosted photo and video management solution. A reflected cross-site scripting (XSS) vulnerability on the /auth/login page allows an attacker to fully compromise any authenticated user's account with a single link click. The vulnerability exists from commit 4ffa26c9 until 4eb1003. The continue query parameter is read from the URL and passed to Sve [truncated]

HIGH immich-app CVE published 2026-04-08

CVE-2026-35455

CVE-2026-35455 is a Stored Cross-Site Scripting (XSS) vulnerability in the 360° panorama viewer of Immich, a self-hosted photo and video management solution. Prior to version 2.7.0, an authenticated user can upload an equirectangular image with crafted text, which is extracted by OCR and rendered via innerHTML without sanitization. This allows the execution of arbitrary JavaScript in the browser of any ot [truncated]

MEDIUM immich-app CVE published 2026-04-03

CVE-2026-25118

Immich, a high-performance self-hosted photo and video management solution, is vulnerable to credential disclosure when a user authenticates to a shared album. The application transmits the album password within the URL query parameters in a GET request to /api/shared-links/me, exposing the password in browser history, proxy and server logs, and referrer headers. This issue allows unintended disclosure of [truncated]