


Perceptive Security
SOC/SIEM Consultancy

immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360° panorama viewer all…
Published:
7 April 2026 at 22:00:00
Alert date:
8 April 2026 at 20:02:46
Source:
nvd.nist.gov
Web Technologies
A stored cross-site scripting (XSS) vulnerability in immich photo management solution prior to version 2.7.0 affects the 360° panorama viewer. Authenticated users can upload malicious equirectangular images with crafted text that gets processed by OCR. The panorama viewer renders this text via innerHTML without sanitization, allowing arbitrary JavaScript execution. This enables session hijacking through persistent API key creation, private photo exfiltration, and access to GPS location history and face biometric data. The vulnerability requires the OCR overlay to be enabled and affects any user who views the malicious panorama.
Technical details
Mitigation steps:
Affected products:
immich
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35455
https://github.com/immich-app/immich/security/advisories/GHSA-9qx4-67jm-cc66
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
