github openVESSL/Anchorr v1.5.1
v1.5.1 — Security patch (GHSA-ph98-5xm3-37w3)

7 hours ago

🔒 Security

  • Fix credential exfiltration via SSRF in config-test endpoints (GHSA-ph98-5xm3-37w3): The POST /test-seerr, /seerr/quality-profiles, /seerr/servers, and POST /jellyfin-libraries endpoints would forward the real stored API key to any URL supplied by an authenticated user. The real key is now only substituted when the submitted URL's host matches the currently configured server host — if they differ, the request is rejected with 403. Thanks to @whoopsi-daisy for the responsible disclosure.

AI-assisted documentation. Code logic manually verified.

Don't miss a new Anchorr release

NewReleases is sending notifications on new releases.