Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 09 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Immich-app
Immich-app immich |
|
| Vendors & Products |
Immich-app
Immich-app immich |
Wed, 08 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360° panorama viewer allows any authenticated user to execute arbitrary JavaScript in the browser of any other user who views the malicious panorama with the OCR overlay enabled. The attacker uploads an equirectangular image containing crafted text; OCR extracts it, and the panorama viewer renders it via innerHTML without sanitization. This enables session hijacking (via persistent API key creation), private photo exfiltration, and access to GPS location history and face biometric data. This vulnerability is fixed in 2.7.0. | |
| Title | immich has Stored XSS via OCR Text in 360° Panorama Viewer | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-10T03:55:33.544Z
Reserved: 2026-04-02T19:25:52.193Z
Link: CVE-2026-35455
Updated: 2026-04-09T14:17:55.975Z
Status : Undergoing Analysis
Published: 2026-04-08T19:25:24.357
Modified: 2026-04-09T15:16:11.303
Link: CVE-2026-35455
No data.
OpenCVE Enrichment
Updated: 2026-04-09T08:27:45Z