PT-2026-51576 · Immich · Immich
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
immich versions 4ffa26c9 through 4eb1003
Description
A reflected cross-site scripting (XSS) issue exists on the '/auth/login' page. The
continue query parameter is processed by SvelteKit's redirect() function without proper scheme or origin validation. This allows an attacker to execute arbitrary JavaScript within the application's origin by sending a crafted link to an authenticated user. The executed script can utilize the victim's active session to create an API key with full permissions, resulting in a persistent account takeover.Recommendations
Update to commit 4eb1003 or later.
Exploit
Fix
XSS
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Immich