CVE-2026-35455Disclosure(futo / immich)

LOWCVSS 5.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360° panorama viewer allows any authenticated user to execute arbitrary JavaScript in the browser of any other user who views the malicious panorama with the OCR overlay enabled. The attacker uploads an equirectangular image containing crafted text; OCR extracts it, and the panorama viewer renders it via innerHTML without sanitization. This enables session hijacking (via persistent API key creation), private photo exfiltration, and access to GPS location history and face biometric data. This vulnerability is fixed in 2.7.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • immich

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
immich

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-08: 3Technical Details · 2026-04-08: 304-08
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Full discourse3 posts
  • AISafe Labs@aisafe_io
    Disclosure

    AISafe Labs found a 🔥 Stored XSS in Immich's 360° panorama viewer (CVE-2026-35455) 🔥 Any user can upload a panorama with text in it. OCR reads the text, then the viewer renders that text as raw HTML. Attacker JS runs against any victim who views the photo. More details 👇🧵 https://t.co/VNmc62LDM6

    Post summary

    AISafe Labs disclosed a stored XSS (CVE‑2026‑35455) in Immich’s panorama viewer where user‑uploaded panoramas with malicious text can execute arbitrary JavaScript in any victim’s browser.

    130101622
    79 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-35455 Stored XSS in Immich Panorama Viewer Prior to Version 2.7.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35455

    Post summary

    The post identifies a stored XSS vulnerability (CVE‑2026‑35455) affecting Immich Panorama Viewer prior to v2.7.0, but provides no additional technical, exploit, or mitigation details.

    0001063
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35455 immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360° panorama viewer allows an… https://www.cve.org/CVERecord?id=CVE-2026-35455

    Post summary

    The post announces CVE‑2026‑35455 as a stored XSS flaw in immich’s 360° panorama viewer prior to version 2.7.0, with no evidence of active exploitation or mitigations provided.

    00010314
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfutoimmich-docker-

Explore more