CVE-2026-105764: Immich: Authenticated SVG upload reaches ImageMagick coders and enables RCE
Immich is a high-performance self-hosted photo and video management solution. Prior to 3.2.4, an authenticated non-admin user could upload SVG files that thumbnail-generation code in server/src/repositories/media.repository.ts passed to libvips. Files that bypassed libvips' native SVG loader fell through to ImageMagick, where attacker-controlled <image href> values reached unrestricted MSL and VIDEO coder operations. By storing one crafted asset and referencing its path from a second delayed-marker SVG, an attacker could execute code in the immich-server container when thumbnail processing ran. This issue is fixed in version 3.2.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Immichto a version that resolves this vulnerability.Fixed in 3.2.4
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated non-admin Immich user can exploit it. The attacker needs the ability to upload crafted SVG assets and have thumbnail processing run.
Which deployments are affected?
Immich versions prior to 3.2.4 are affected. The vulnerable processing occurs in the immich-server container when thumbnail-generation code passes applicable SVG uploads through libvips and then ImageMagick.
What is the impact if exploitation succeeds?
A successful attacker can execute code in the immich-server container. The described technique uses one stored crafted asset and a second SVG containing a delayed marker that references the stored asset path.
What should teams do to remediate the issue?
Upgrade Immich to version 3.2.4, which fixes the issue. The provided data does not identify a configuration workaround for environments that cannot immediately upgrade.