PT-2026-33001 · Immich · Immich

Published

2026-04-14

·

Updated

2026-04-15

·

CVE-2026-40096

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions immich versions prior to 2.7.3
Description An open redirect exists in the shared album functionality. A registered attacker can create a shared album with a crafted name containing a malicious payload. This payload is inserted unsanitized into a tag within 'api.service.ts'. When a victim opens the share link, the browser renders the payload in the tag, causing a redirect to an attacker-controlled site. This can be used to facilitate phishing attacks by directing users to a fake authentication page to collect login credentials.
Recommendations Update to version 2.7.3.

Fix

XSS

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40096

Affected Products

Immich