---
id: CVE-2026-105764
title: Immich is a high-performance self-hosted photo and video management solution
summary: >-
  Immich is a high-performance self-hosted photo and video management solution.
  Prior to 3.2.4, an authenticated non-admin user could upload SVG files that
  thumbnail-generation code in server/src/repositories/media.repository.ts
  passed to …
severity: high
cvss: 7.7
cvssVector: 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-94
vendor: immich-app
product: immich
affected:
  - immich < 3.2.4
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T00:16:33.577'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105764'
references:
  - url: 'https://github.com/immich-app/immich/releases/tag/v3.2.4'
    label: security-advisories@github.com
  - url: >-
      https://github.com/immich-app/immich/security/advisories/GHSA-q89f-h332-8q2h
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-05T23:36:21.189Z'
---

## Overview

Immich is a high-performance self-hosted photo and video management solution. Prior to 3.2.4, an authenticated non-admin user could upload SVG files that thumbnail-generation code in server/src/repositories/media.repository.ts passed to libvips. Files that bypassed libvips' native SVG loader fell through to ImageMagick, where attacker-controlled &lt;image href&gt; values reached unrestricted MSL and VIDEO coder operations. By storing one crafted asset and referencing its path from a second delayed-marker SVG, an attacker could execute code in the immich-server container when thumbnail processing ran. This issue is fixed in version 3.2.4.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
