CVE Explorer
CVE-2026-35455
immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360° panorama viewer allows any authenticated user to execute arbitrary JavaScript in the browser of any other user who views the malicious panorama with the OCR overlay enabled. The attacker uploads an equirectangular image containing crafted text; OCR extracts it, and the panorama viewer renders it via innerHTML without sanitization. This enables session hijac
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"immich","vendor":"immich-app","versions":[{"status":"affected","version":"< 2.7.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d2d80e030ef88be6da4fa7740b47a8d33eec4b00edcd18093ce3116b26c96c31 · sha256:421b88c9ea16cf10… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d2d80e030ef88be6da4fa7740b47a8d33eec4b00edcd18093ce3116b26c96c31 · sha256:421b88c9ea16cf10… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d2d80e030ef88be6da4fa7740b47a8d33eec4b00edcd18093ce3116b26c96c31 · sha256:421b88c9ea16cf10… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/immich-app/immich/security/advisories/GHSA-9qx4-67jm-cc66","tags":["x_refsource_CONFIRM"],"url":"https://github.com/immich-app/immich/security/advisories/GHSA-9qx4-67jm-cc66"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d2d80e030ef88be6da4fa7740b47a8d33eec4b00edcd18093ce3116b26c96c31 · sha256:421b88c9ea16cf10… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.