PT-2026-26545 · Anchor · Anchor

Xdnewlun1

·

Published

2026-03-20

·

Updated

2026-03-22

·

CVE-2026-32890

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Anchorr versions 1.4.1 and below
Description Anchorr is a Discord bot used for requesting movies and TV shows and receiving notifications about media server updates. A stored Cross-site Scripting (XSS) issue exists in the web dashboard's User Mapping dropdown, allowing any unprivileged Discord user within the configured guild to execute arbitrary JavaScript in the Anchorr administrator's browser. This can be chained with the GET /api/config endpoint, which returns all secrets in plaintext. An attacker can potentially exfiltrate credentials including DISCORD TOKEN, JELLYFIN API KEY, JELLYSEERR API KEY, JWT SECRET, WEBHOOK SECRET, and bcrypt password hashes without authentication to Anchorr.
Recommendations Update to version 1.4.2 or later.

Exploit

Fix

Information Disclosure

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-32890
GHSA-QPMQ-6WJC-W28Q

Affected Products

Anchor