Lychee Cross-User Authorization Vulnerability in Album Password Unlock Functionality

Vulnerability

A vulnerability in Lychee photo management tool, prior to version 7.1.0, allows users to gain unauthorized access to other users' password-protected albums. This issue arises because, when a user unlocks a password-protected public album, all other public albums with the same password are also unlocked, creating a complete authorization bypass. The vulnerability is rooted in the album password propagation feature, which was intended to enhance user experience but inadvertently compromised privacy and security in multi-user scenarios.

Impact

Exploitation of this vulnerability allows unauthorized access to private photos and content in other users' password-protected albums, exposing all album contents, metadata, and photos to unauthorized users.

Reproduction

To reproduce this vulnerability, unlock a password-protected public album on a multi-user Lychee installation. The system will automatically unlock all other public albums with the same password, bypassing authorization checks and granting access to potentially sensitive content.

Remediation

Users are advised to update to Lychee version 7.1.0, where this vulnerability has been fixed.

Added: Jan 12, 2026, 7:18 PM
Updated: Jan 12, 2026, 7:18 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
0.6
exploitability
7.2
remediation
7.7
relevance
2.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.