Repository navigation
Security: LycheeOrg/Lychee
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Global checksum deduplication lets uploaders modify other users' private photosGHSA-w9wh-fx9f-q2vw published
Sep 29, 2026 by ildyriaModerate -
Stored same-origin XSS via SVG/XML uploaded as an album trackGHSA-xc46-cv6w-m8q8 published
Sep 29, 2026 by ildyriaHigh -
SSRF filter bypass in Import via URL: denylist omits NAT64 range (64:ff9b::/96)GHSA-fq22-83fg-8wv5 published
Sep 29, 2026 by ildyriaLow -
Authenticated users can rename other users' WebAuthn credential aliases via an IDORGHSA-cgg4-g7rg-865f published
Sep 27, 2026 by ildyriaModerate -
Stored XSS in LiveMetrics preview via album titles when PAYPAL_CLIENT_ID is setGHSA-v49p-2pgg-xv3m published
Sep 29, 2026 by ildyriaHigh -
Edit-only album collaborators can copy restricted photos into owned albums and access their originalsGHSA-pw32-v9r5-85hc published
Sep 29, 2026 by ildyriaHigh -
Revoked album access still permits private TagAlbum thumbnail retrieval via stale per-user cacheGHSA-wf4v-4cqh-g7p7 published
Sep 27, 2026 by ildyriaModerate -
Pending guest uploads can be published before moderation via ZIP downloads and landing backgroundsGHSA-mf2c-48xf-pwwm published
Sep 25, 2026 by ildyriaModerate -
Edit-only album collaborators can take ownership of or delete a shared album subtree via move and mergeGHSA-jp9x-63pp-pv4v published
Sep 29, 2026 by ildyriaHigh -
Batch authorization bypass lets uploaders change license metadata on other users' Unsorted photosGHSA-9jq3-r56w-x53c published
Sep 25, 2026 by ildyriaModerate