Impact
Immich versions up to 3.1.0 allow assets that are explicitly locked through the single‑asset endpoint to still be returned to a user via shared albums or shared links. The flaw removes the visibility restriction that an attacker would otherwise rely on, allowing anyone who can access a pre‑existing shared album or link to read the locked file data and its associated metadata. The weakness is a failure to enforce access control on locked assets.
Affected Systems
The vulnerability applies to the Immich application from the vendor immich-app. All installations running version 3.1.0 or earlier are affected; the specific functionality impacted is the asset locking mechanism exposed through album and link sharing.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity data‑exposure risk. EPSS information is unavailable, so exploitation likelihood cannot be quantified from available data, yet the flaw is exploitable by any party who can access an album or link that contains a locked asset. The vulnerability is not currently listed in CISA KEV, but the presence of a public GitHub discussion and a community advisory suggests that attackers may have identified the flaw. The exploit path requires prior exposure of a shared album or link; no additional privileges or software execution are required.
OpenCVE Enrichment