{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "3.2.4"
              }
            ],
            "source": "AFFECTED_FIELD"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "db355f79d910bbfc6378117ed10868493c97b922"
            }
          ],
          "repo": "https://github.com/immich-app/immich",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-q89f-h332-8q2h"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-94"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105764.json"
  },
  "details": "Immich is a high-performance self-hosted photo and video management solution. Prior to 3.2.4, an authenticated non-admin user could upload SVG files that thumbnail-generation code in server/src/repositories/media.repository.ts passed to libvips. Files that bypassed libvips' native SVG loader fell through to ImageMagick, where attacker-controlled \u0026lt;image href\u0026gt; values reached unrestricted MSL and VIDEO coder operations. By storing one crafted asset and referencing its path from a second delayed-marker SVG, an attacker could execute code in the immich-server container when thumbnail processing ran. This issue is fixed in version 3.2.4.",
  "id": "CVE-2026-105764",
  "modified": "2026-10-06T10:31:06.667293086Z",
  "published": "2026-10-05T23:07:38.844Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105764.json"
    },
    {
      "type": "WEB",
      "url": "https://github.com/immich-app/immich/releases/tag/v3.2.4"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/immich-app/immich/security/advisories/GHSA-q89f-h332-8q2h"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-105764"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Immich: Authenticated SVG upload reaches ImageMagick coders and enables RCE"
}