
CVE-2026-33738 Lychee is a free, open-source photo-management tool. Prior to version 7.5.3, the photo `description` field is stored without HTML sanitization and rendered using `{!!… https://www.cve.org/CVERecord?id=CVE-2026-33738
Post summary
The text announces the existence of CVE-2026-33738 in Lychee, detailing an XSS flaw and indicating that versions prior to 7.5.3 are vulnerable, but it does not provide a PoC, exploit code, or evidence of active exploitation.
