CVE-2026-32890Disclosure(openvessl / anchorr)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openvessl anchorr systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and below, a stored Cross-site Scripting (XSS) vulnerability in the web dashboard's User Mapping dropdown allows any unprivileged Discord user in the configured guild to execute arbitrary JavaScript in the Anchorr admin's browser. By chaining this with the GET /api/config endpoint (which returns all secrets in plaintext), an attacker can exfiltrate every credential stored in Anchorr which includes DISCORD_TOKEN, JELLYFIN_API_KEY, JELLYSEERR_API_KEY, JWT_SECRET, WEBHOOK_SECRET, and bcrypt password hashes without any authentication to Anchorr itself. This issue has been fixed in version 1.4.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • anchorr

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-03-20); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
anchorr

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-20: 4Mentions · 2026-03-22: 1Mentions · 2026-07-05: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-07-05: 1Technical Details · 2026-03-20: 3Technical Details · 2026-03-22: 103-2003-2207-05
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-204
Disclosure2General1Patch1
2026-03-221
Disclosure1
2026-07-051
General1
Full discourse6 posts
  • 靁冰@Ryeheauh
    General

    discordメンテナのみなさまー CVE-2025-26604 CVE-2026-32890 CVE-2025-53943 CVE-2024-21663 CVE-2020-26249 botとかモジュールに上記セキュリティ勧告出ていますよ お使いのbotに上記のリスクが含まれてないかご確認をー

    Post summary

    The message lists several CVEs and urges Discord maintainers to check bots/modules for risk, noting that security advisories exist but providing no technical or exploit details.

    0000072
    72 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32890 - Critical Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and below, a stored Cross-site Scripting ... https://www.thehackerwire.com/vulnerability/CVE-2026-32890/ https://t.co/XGnRMk4L8M

    Post summary

    CVE-2026-32890 is a critical stored XSS flaw affecting Anchorr Discord bot version 1.4.1 and earlier, enabling attackers to execute cross‑site scripts on the platform.

    0000036
    142 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32890: Anchorr: Stored XSS in User Mapp... Any Discord user can drop XSS payloads into User Mapping dropdown, then chain with unauthenticated /api/config to dump ... https://zerodaysignal.com/vulnerability/CVE-2026-32890 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post discloses a stored XSS vulnerability in Anchorr’s User Mapping interface, enabling any Discord user to inject payloads and then retrieve sensitive configuration data through an unauthenticated API endpoint.

    0000070
    155 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32890 Stored XSS in Anchorr Discord Bot Leads to Credential Exfiltration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32890

    Post summary

    A stored XSS vulnerability in the Anchorr Discord Bot was disclosed, potentially enabling credential exfiltration.

    0000058
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32890 Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and below, a stored … https://www.cve.org/CVERecord?id=CVE-2026-32890

    Post summary

    The snippet briefly notes CVE-2026-32890 for the Anchorr Discord bot, mentioning affected versions but providing no further detail on exploitation, patching, or technical specifics.

    00000317
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32890: CRITICAL] Discord bot Anchorr had a serious Cross-Site Scripting (XSS) vulnerability in versions 1.4.1 and below, allowing attackers to gain access to sensitive credentials. Update to versio...#cve,CVE-2026-32890,#cybersecurity https://cvefind.com/CVE-2026-32890

    Post summary

    The tweet announces a critical XSS flaw in Discord bot Anchorr (v1.4.1 and earlier), notes that it can expose credentials, and advises users to update to a newer version.

    00000302
    604 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenvesslanchorr---

Explore more