CVE-2026-53662 is a critical vulnerability in Immich, a self-hosted photo and video management solution. A reflected cross-site scripting (XSS) vulnerability on the /auth/login page allows an attacker to fully compromise any authenticated user's account with a single link click. The vulnerability exists from commit 4ffa26c9 until 4eb1003. The continue query parameter is read from the URL and passed to Sve [truncated]
CVE-2026-35455 is a Stored Cross-Site Scripting (XSS) vulnerability in the 360° panorama viewer of Immich, a self-hosted photo and video management solution. Prior to version 2.7.0, an authenticated user can upload an equirectangular image with crafted text, which is extracted by OCR and rendered via innerHTML without sanitization. This allows the execution of arbitrary JavaScript in the browser of any ot [truncated]
Immich, a high-performance self-hosted photo and video management solution, is vulnerable to credential disclosure when a user authenticates to a shared album. The application transmits the album password within the URL query parameters in a GET request to /api/shared-links/me, exposing the password in browser history, proxy and server logs, and referrer headers. This issue allows unintended disclosure of [truncated]