Metrics
Affected Vendors & Products
Wed, 15 Apr 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Futo
Futo immich |
|
| CPEs | cpe:2.3:a:futo:immich:*:*:*:*:*:docker:*:* | |
| Vendors & Products |
Futo
Futo immich |
Mon, 13 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Thu, 09 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Immich-app
Immich-app immich |
|
| Vendors & Products |
Immich-app
Immich-app immich |
Wed, 08 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360° panorama viewer allows any authenticated user to execute arbitrary JavaScript in the browser of any other user who views the malicious panorama with the OCR overlay enabled. The attacker uploads an equirectangular image containing crafted text; OCR extracts it, and the panorama viewer renders it via innerHTML without sanitization. This enables session hijacking (via persistent API key creation), private photo exfiltration, and access to GPS location history and face biometric data. This vulnerability is fixed in 2.7.0. | |
| Title | immich has Stored XSS via OCR Text in 360° Panorama Viewer | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-04-08T18:31:27.418Z
Updated: 2026-04-13T15:36:26.045Z
Reserved: 2026-04-02T19:25:52.193Z
Link: CVE-2026-35455
Updated: 2026-04-09T14:17:55.975Z
Status : Analyzed
Published: 2026-04-08T19:25:24.357
Modified: 2026-04-15T18:38:01.113
Link: CVE-2026-35455
No data.