CVE-2026-35455: immich has Stored XSS via OCR Text in 360° Panorama Viewer
immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360° panorama viewer allows any authenticated user to execute arbitrary JavaScript in the browser of any other user who views the malicious panorama with the OCR overlay enabled. The attacker uploads an equirectangular image containing crafted text; OCR extracts it, and the panorama viewer renders it via innerHTML without sanitization. This enables session hijacking (via persistent API key creation), private photo exfiltration, and access to GPS location history and face biometric data. This vulnerability is fixed in 2.7.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
immich (360° panorama viewer)to a version that resolves this vulnerability.Fixed in 2.7.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35455?
CVE-2026-35455 has a severity rating of 7.3, classified as high.
How do I fix CVE-2026-35455?
To fix CVE-2026-35455, update your Immich installation to version 2.7.0 or later.
What type of vulnerability is CVE-2026-35455?
CVE-2026-35455 is a Stored Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-35455?
Any authenticated user of the Immich 360° panorama viewer prior to version 2.7.0 is affected by CVE-2026-35455.
What impact does CVE-2026-35455 have?
CVE-2026-35455 allows an attacker to execute arbitrary JavaScript in the browsers of other users viewing the malicious panorama.