Reflected Cross-Site Scripting Vulnerability in Immich Photo Management Solution
CVE-2026-53662

9.6CRITICAL

Key Information:

Vendor

Immich-app

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-53662?

Immich, a self-hosted photo and video management solution, contains a reflected cross-site scripting vulnerability on the /auth/login page, which allows attackers to exploit the application without proper validation of URL parameters. By leveraging the continue query parameter, an attacker can inject malicious JavaScript that executes within Immich's context. This can lead to account compromise, as the malware can generate a new API key with full user permissions, enabling persistent access to the victim's account. This vulnerability was addressed in the code commit 4eb1003.

Affected Version(s)

immich >= main@4ffa26c9, < main@4eb1003

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.