top of page
perceptive_background_267k.jpg

immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360° panorama viewer all…

Published:

7 April 2026 at 22:00:00

Alert date:

8 April 2026 at 22:09:50

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Data Breach & Exfiltration

A stored cross-site scripting (XSS) vulnerability in immich photo management solution affects versions prior to 2.7.0. The vulnerability exists in the 360° panorama viewer where authenticated users can upload malicious equirectangular images containing crafted text. When OCR processes these images and the panorama viewer renders the extracted text via innerHTML without proper sanitization, it allows arbitrary JavaScript execution in other users' browsers. This can lead to session hijacking through persistent API key creation, private photo exfiltration, and unauthorized access to GPS location history and biometric face data. The vulnerability requires the OCR overlay to be enabled and affects any user viewing the malicious panorama.

Technical details

Mitigation steps:

Affected products:

immich

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page