Executive brief
Immich, a self-hosted photo and video management platform, contains a security flaw in how it handles passwords for shared albums. When a user enters a password to view a shared album, the system sends that password as part of the web address (URL) rather than hiding it. This means the password could be recorded in browser history, server logs, or network security logs, potentially allowing unauthorized individuals to access private photos and videos.
Technical details
Immich prior to version 2.6.0 is vulnerable to CWE-598 (Use of GET Request Method with Sensitive Query Strings). When a user authenticates to a shared album, the application transmits the album password within the URL query parameters of a GET request to the `/api/shared-links/me` endpoint. Because query parameters are frequently logged by web servers, reverse proxies, and browser histories, this practice exposes sensitive credentials to anyone with access to those logs. An attacker who obtains these logs could gain unauthorized access to shared albums and the sensitive media contained within. The issue is resolved in version 2.6.0 by changing how authentication data is transmitted.
Affected products
- immich-app Immich < 2.6.0
Timeline
- 2026-04-02: advisory: Vendor security advisory published on GitHub
- 2026-04-03: disclosed: CVE-2026-25118 published to NVD
- 2026-03-19: patched: Version 2.6.0 released with fix