CVE-2026-32890 is a critical stored Cross-site Scripting (XSS) vulnerability affecting Anchorr Discord bot versions 1.4.1 and below. Rated 9.6 CVSS Critical, this flaw allows any unprivileged Discord user to execute arbitrary JavaScript in an administrator's browser. This can be chained to exfiltrate all sensitive credentials, including API keys and password hashes, from Anchorr without requiring authentication. While no public exploit code or active exploitation has been observed, the vulnerability has received minimal community discussion. The issue has been fixed in Anchorr version 1.4.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4.1CPE matchmatch criteria | cpe:2.3:a:openvessl:anchorr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.