FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

immich -- open redirect and reflected XSS in maintenance endpoint

Affected packages
immich < 3.2.0

Details

VuXML ID fcc6baaa-adbc-11f1-a655-3497f65b111b
Discovery 2026-08-23
Entry 2026-09-11

The immich project reports:

The /maintenance endpoint fails to validate the continue URL parameter. When maintenance mode is disabled, which is the default, the application accepts unvalidated redirect targets, enabling both open redirects and reflected cross-site scripting. An unauthenticated user can craft a malicious link leading to account takeover, including administrative accounts, through same-origin API requests with credentials.

References

URL https://github.com/immich-app/immich/security/advisories/GHSA-h5w4-vjv4-9r5q