No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 15 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Immich-app
Immich-app immich |
|
| Vendors & Products |
Immich-app
Immich-app immich |
Wed, 15 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | immich is a high performance self-hosted photo and video management solution. Versions prior to 2.7.3 contain an open redirect vulnerability in the shared album functionality, where the album name is inserted unsanitized into a <meta> tag in api.service.ts. A registered attacker can create a shared album with a crafted name containing 0;url=https://attackersite.com" http-equiv="refresh, which when rendered in the <meta property="og:title"> tag causes the victim's browser to redirect to an attacker-controlled site upon opening the share link. This facilitates phishing attacks, as the attacker could host a modified version of immich that collects login credentials from victims who believe they need to authenticate to view the shared album. This issue has been fixed in version 2.7.3. | |
| Title | immich: Open Redirect via Shared Album name | |
| Weaknesses | CWE-601 CWE-79 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-15T16:19:07.744Z
Reserved: 2026-04-09T01:41:38.536Z
Link: CVE-2026-40096
Updated: 2026-04-15T16:19:03.271Z
Status : Awaiting Analysis
Published: 2026-04-15T04:17:47.680
Modified: 2026-04-17T15:38:09.243
Link: CVE-2026-40096
No data.
OpenCVE Enrichment
Updated: 2026-04-15T13:49:14Z