CVE Explorer
CVE-2026-32890
Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and below, a stored Cross-site Scripting (XSS) vulnerability in the web dashboard's User Mapping dropdown allows any unprivileged Discord user in the configured guild to execute arbitrary JavaScript in the Anchorr admin's browser. By chaining this with the GET /api/config endpoint (which returns all secrets in plaintext), an attacker can exfiltrate eve
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0f09c71699f470475868bd37a5de002fb8fd9b39a7c6fec0986a3ffa1ca55cd1 · sha256:688ab3f46654cda4… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0f09c71699f470475868bd37a5de002fb8fd9b39a7c6fec0986a3ffa1ca55cd1 · sha256:688ab3f46654cda4… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"Anchorr","vendor":"openVESSL","versions":[{"status":"affected","version":"< 1.4.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:0f09c71699f470475868bd37a5de002fb8fd9b39a7c6fec0986a3ffa1ca55cd1 · sha256:688ab3f46654cda4… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.7,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:0f09c71699f470475868bd37a5de002fb8fd9b39a7c6fec0986a3ffa1ca55cd1 · sha256:688ab3f46654cda4… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0f09c71699f470475868bd37a5de002fb8fd9b39a7c6fec0986a3ffa1ca55cd1 · sha256:688ab3f46654cda4… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0f09c71699f470475868bd37a5de002fb8fd9b39a7c6fec0986a3ffa1ca55cd1 · sha256:688ab3f46654cda4… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/openVESSL/Anchorr/commit/d5ae67e5b455241274ed0072cf2db43a6eb3f0b2","tags":["x_refsource_MISC"],"url":"https://github.com/openVESSL/Anchorr/commit/d5ae67e5b455241274ed0072cf2db43a6eb3f0b2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0f09c71699f470475868bd37a5de002fb8fd9b39a7c6fec0986a3ffa1ca55cd1 · sha256:688ab3f46654cda4… · /containers/cna/references/1
{"name":"https://github.com/openVESSL/Anchorr/releases/tag/v1.4.2","tags":["x_refsource_MISC"],"url":"https://github.com/openVESSL/Anchorr/releases/tag/v1.4.2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0f09c71699f470475868bd37a5de002fb8fd9b39a7c6fec0986a3ffa1ca55cd1 · sha256:688ab3f46654cda4… · /containers/cna/references/2
{"tags":["exploit"],"url":"https://github.com/openVESSL/Anchorr/security/advisories/GHSA-qpmq-6wjc-w28q"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0f09c71699f470475868bd37a5de002fb8fd9b39a7c6fec0986a3ffa1ca55cd1 · sha256:688ab3f46654cda4… · /containers/adp/0/references/0
{"name":"https://github.com/openVESSL/Anchorr/security/advisories/GHSA-qpmq-6wjc-w28q","tags":["x_refsource_CONFIRM"],"url":"https://github.com/openVESSL/Anchorr/security/advisories/GHSA-qpmq-6wjc-w28q"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0f09c71699f470475868bd37a5de002fb8fd9b39a7c6fec0986a3ffa1ca55cd1 · sha256:688ab3f46654cda4… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.