PT-2026-33001 · Immich · Immich
Published
2026-04-14
·
Updated
2026-04-15
·
CVE-2026-40096
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
immich versions prior to 2.7.3
Description
An open redirect exists in the shared album functionality. A registered attacker can create a shared album with a crafted name containing a malicious payload. This payload is inserted unsanitized into a tag within 'api.service.ts'. When a victim opens the share link, the browser renders the payload in the tag, causing a redirect to an attacker-controlled site. This can be used to facilitate phishing attacks by directing users to a fake authentication page to collect login credentials.
Recommendations
Update to version 2.7.3.
Fix
XSS
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Immich