Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XSS vulnerability in the Jellyseerr user selector. Jellyseerr allows any account holder to execute arbitrary JavaScript in the Anchorr admin's browser session. The injected script calls the authenticated /api/config endpoint - which returns the full application configuration in plaintext. This allows the attacker to forge a valid Anchorr session token and gain full admin access to the dashboard with no knowledge of the admin password. The same response also exposes the API keys and tokens for every integrated service, resulting in simultaneous account takeover of the Jellyfin media server (via JELLYFIN_API_KEY), the Jellyseerr request manager (via JELLYSEERR_API_KEY), and the Discord bot (via DISCORD_TOKEN). This issue has been fixed in version 1.4.2.
An attacker with any account in Jellyseerr injects malicious JavaScript code into the user selector in the Anchorr interface. When an administrator opens the infected view, the injected script automatically calls the authenticated /api/config endpoint, which returns the complete application configuration as plain text. Based on this response, the attacker obtains the Anchorr session token and API keys for all integrated services: Jellyfin (JELLYFIN_API_KEY), Jellyseerr (JELLYSEERR_API_KEY), and Discord (DISCORD_TOKEN). With this data, they can forge a valid administrator session and take control of all connected services simultaneously.
The attacker gains full administrator access to the Anchorr panel and simultaneously takes over accounts on the Jellyfin media server, Jellyseerr request manager, and Discord bot without needing to know any password. Additionally, complete application configuration is disclosed along with all secret API keys.
Update Anchorr to version 1.4.2, where the vulnerability has been fixed. After updating, it is recommended to invalidate and rotate all API keys and tokens for Jellyfin, Jellyseerr, and Discord services, as they may have been previously compromised.
Anchorr (openVESSL) in versions 1.4.1 and earlier
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HOpenvessl Anchorr
APPOpenvessl≤ 1.4.1