CVE-2026-105764: high-severity vulnerability in immich-app immich
Immich: Authenticated SVG upload reaches ImageMagick coders and enables RCE
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.7epss 0.3%
exploitation probability
0.3%top 83% of all CVEs
observed exploitation
nono source reports it
Immich is a high-performance self-hosted photo and video management solution. Prior to 3.2.4, an authenticated non-admin user could upload SVG files that thumbnail-generation code in server/src/repositories/media.repository.ts passed to libvips. Files that bypassed libvips' native SVG loader fell through to ImageMagick, where attacker-controlled <image href> values reached unrestricted MSL and VIDEO coder operations. By storing one crafted asset and referencing its path from a second delayed-marker SVG, an attacker could execute code in the immich-server container when thumbnail processing ran. This issue is fixed in version 3.2.4.
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
immich-app · immichRelated CVEs — immich-app immich
In the same product, most dangerous first.
CVE-2026-59258HIGHimmich < 3.0.3 Shared Album Editor Ownership Takeover via updateUserEPSS 0.5%CVE-2026-25118MEDIUMimmich-server: Insecure Transmission of Authentication Credentials via Password Parameter in HTTP Request Query String When Accessing Shared AlbumsEPSS 0.4%CVE-2026-82272HIGHImmich Locked Assets Remain Readable Through Albums and Shared LinksEPSS 0.4%CVE-2026-53662CRITICALimmich: One-click account takeover via XSS in login page continue redirectEPSS 0.4%CVE-2025-43856HIGHimmich allows account hijacking through oauth2EPSS 0.4%CVE-2026-23896HIGHimmich API Key Privilege Escalation vulnerabilityEPSS 0.3%