VulnCheck reports:
Immich through 3.1.0 fails to properly enforce locked asset
visibility when assets are locked through the single-asset
endpoint, allowing them to remain accessible through shared
albums and links.
In 3.2.2 the single-asset endpoint still lacks the album removal
that the bulk endpoint performs, and the album and shared link
access checks still carry no visibility filter. Both code paths
of the web interface use the bulk endpoint, so the state can only
be reached by calling the API directly, and such assets stay
visible only to those the owner already shares the album or the
link with. The identifier was assigned by VulnCheck, not by the
immich project, which has published no advisory and has not
confirmed the report. NVD has not analysed the entry.