PT-2026-51576 · Immich · Immich

·

CVE-2026-53662

·

Published

2026-06-23

·

Updated

2026-06-25

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions immich versions 4ffa26c9 through 4eb1003
Description A reflected cross-site scripting (XSS) issue exists on the '/auth/login' page. The continue query parameter is processed by SvelteKit's redirect() function without proper scheme or origin validation. This allows an attacker to execute arbitrary JavaScript within the application's origin by sending a crafted link to an authenticated user. The executed script can utilize the victim's active session to create an API key with full permissions, resulting in a persistent account takeover.
Recommendations Update to commit 4eb1003 or later.

Exploit

Fix

XSS

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53662
GHSA-8244-8VPR-VP9C

Affected Products

Immich