top of page
perceptive_background_267k.jpg

immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360° panorama viewer all…

Published:

7 april 2026 om 22:00:00

Alert date:

8 april 2026 om 20:02:46

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

A stored cross-site scripting (XSS) vulnerability in immich photo management solution prior to version 2.7.0 affects the 360° panorama viewer. Authenticated users can upload malicious equirectangular images with crafted text that gets processed by OCR. The panorama viewer renders this text via innerHTML without sanitization, allowing arbitrary JavaScript execution. This enables session hijacking through persistent API key creation, private photo exfiltration, and access to GPS location history and face biometric data. The vulnerability requires the OCR overlay to be enabled and affects any user who views the malicious panorama.

Technical details

Mitigation steps:

Affected products:

immich

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page