PT-2026-26545 · Anchor · Anchor

Xdnewlun1

·

Publicado

2026-03-20

·

Atualizado

2026-03-22

·

CVE-2026-32890

CVSS v3.1

9.6

Crítica

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Anchorr versions 1.4.1 and below
Description Anchorr is a Discord bot used for requesting movies and TV shows and receiving notifications about media server updates. A stored Cross-site Scripting (XSS) issue exists in the web dashboard's User Mapping dropdown, allowing any unprivileged Discord user within the configured guild to execute arbitrary JavaScript in the Anchorr administrator's browser. This can be chained with the GET /api/config endpoint, which returns all secrets in plaintext. An attacker can potentially exfiltrate credentials including DISCORD TOKEN, JELLYFIN API KEY, JELLYSEERR API KEY, JWT SECRET, WEBHOOK SECRET, and bcrypt password hashes without authentication to Anchorr.
Recommendations Update to version 1.4.2 or later.

Exploit

Correção

Information Disclosure

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32890
GHSA-QPMQ-6WJC-W28Q

Produtos afetados

Anchor