Reflected Cross-Site Scripting Vulnerability in Immich Photo Management Solution
CVE-2026-53662
9.6CRITICAL
What is CVE-2026-53662?
Immich, a self-hosted photo and video management solution, contains a reflected cross-site scripting vulnerability on the /auth/login page, which allows attackers to exploit the application without proper validation of URL parameters. By leveraging the continue query parameter, an attacker can inject malicious JavaScript that executes within Immich's context. This can lead to account compromise, as the malware can generate a new API key with full user permissions, enabling persistent access to the victim's account. This vulnerability was addressed in the code commit 4eb1003.
Affected Version(s)
immich >= main@4ffa26c9, < main@4eb1003
