CVE-2026-105764
Deferred Deferred - Pending Action

Authenticated SVG File Upload Leading to Remote Code Execution in Immich

Vulnerability report for CVE-2026-105764, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Immich is a high-performance self-hosted photo and video management solution. Prior to 3.2.4, an authenticated non-admin user could upload SVG files that thumbnail-generation code in server/src/repositories/media.repository.ts passed to libvips. Files that bypassed libvips' native SVG loader fell through to ImageMagick, where attacker-controlled <image href> values reached unrestricted MSL and VIDEO coder operations. By storing one crafted asset and referencing its path from a second delayed-marker SVG, an attacker could execute code in the immich-server container when thumbnail processing ran. This issue is fixed in version 3.2.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
immich-app immich < 3.2.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105764 is a remote code execution vulnerability in Immich versions prior to 3.2.4. An authenticated non-admin user can upload a malicious SVG file that bypasses libvips' SVG loader and is processed by ImageMagick instead. ImageMagick's SVG renderer then interprets attacker-controlled image href values as arbitrary coder inputs, allowing code execution in the Immich server container.

Detection Guidance

Check for unauthorized SVG uploads in your Immich instance by reviewing uploaded files for unexpected or malicious SVG content. Inspect server logs for ImageMagick or libvips processing errors during thumbnail generation. Look for files with unusual paths or references in the <image href> tags within SVG files.

Impact Analysis

This vulnerability allows an attacker to execute arbitrary code within the Immich server container. This could lead to full container compromise, unauthorized access to sensitive data, and potential lateral movement within the network if the container has elevated privileges.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles and HIPAA's security requirements. It may result in data breaches, unauthorized data processing, and failure to maintain data integrity and confidentiality.

Mitigation Strategies

Upgrade Immich to version 3.2.4 or later immediately. Disable SVG uploads if not required. If SVG uploads are necessary, use an isolated renderer for processing. Set VIPS_BLOCK_UNTRUSTED environment variable. Remove vips-magick from the build. Apply a restrictive ImageMagick policy. Run the container as a non-root user with a read-only filesystem.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105764. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart