CVE-2026-32891 | openVESSL Anchorr up to 1.4.1 /api/config JELLYFIN_API_KEY cross site scripting (GHSA-6mg4-788h-7g9g)
A vulnerability identified as problematic has been detected in openVESSL Anchorr up to 1.4.1. This vulnerability affects unknown code of the file /api/config. This manipulation of the argument JELLYFIN_API_KEY causes basic cross site scripting.
This vulnerability is handled as CVE-2026-32891. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.