CVE-2026-32890 | openVESSL Anchorr up to 1.4.1 /api/config cross site scripting (GHSA-qpmq-6wjc-w28q)
A vulnerability was found in openVESSL Anchorr up to 1.4.1. It has been classified as problematic. Impacted is an unknown function of the file /api/config. This manipulation of the argument DISCORD_TOKEN/JELLYFIN_API_KEY/JELLYSEERR_API_KEY/JWT_SECRET/WEBHOOK_SECRET causes cross site scripting.
This vulnerability is registered as CVE-2026-32890. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.