Executive brief
LibrePhotos, a self-hosted photo management service, contains a security flaw that allows logged-in users to view other people's private photos. By manipulating the photo-sharing feature, an attacker can grant themselves access to images they do not own or remove access from legitimate users. This could lead to the unauthorized exposure of private personal data and family photos stored on the platform.
Technical details
A Broken Object Level Authorization (BOLA) vulnerability, also known as Insecure Direct Object Reference (IDOR), exists in the `SetPhotosShared` endpoint of LibrePhotos. The root cause is a missing ownership validation check in the backend API; while sibling endpoints (like SetPhotosFavorite) filter queries by `owner=request.user`, the sharing endpoint resolved photos solely by their image hash. An authenticated attacker who knows or can guess a victim's photo image hash can manipulate the `shared_to` relation to add their own user ID, thereby gaining read access through the media-serving views. The vulnerability also allows an attacker to strip legitimate shares from a victim's photos. This issue was addressed in version 1.0.0 by enforcing owner scoping on both the share and unshare branches.
Affected products
- LibrePhotos LibrePhotos before 1.0.0
Timeline
- 2026-06-13: disclosed: Issue reported on GitHub
- 2026-06-21: patched: Fix merged into dev branch via pull request 1866
- 2026-06-29: advisory: CVE published to NVD
References
- https://github.com/LibrePhotos/librephotos/commit/325bd1f5fda71c6d56737aa09cfce0cb8106675a
- https://github.com/LibrePhotos/librephotos/issues/1860
- https://github.com/LibrePhotos/librephotos/pull/1866
- https://github.com/LibrePhotos/librephotos/releases/tag/1.0.0
- https://www.vulncheck.com/advisories/librephotos-insecure-direct-object-reference-in-setphotosshared-endpoint