๐Ÿ” CVE Alert

CVE-2026-108580

MEDIUM 6.5

AniWorld Downloader before 5.3.0 WebUI Login Brute Force via /login

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

AniWorld Downloader before 5.3.0 contains an improper restriction of authentication attempts vulnerability in the WebUI /login POST handler that allows unauthenticated attackers to guess passwords without throttling. Attackers can enumerate usernames through verify_user response timing and brute-force passwords on exposed WebUI instances to take over accounts.

CWE CWE-307
Vendor phoenixthrush
Product aniworld downloader
Published Oct 10, 2026
Stay Ahead of the Next One

Get instant alerts for phoenixthrush aniworld downloader

Be the first to know when new medium vulnerabilities affecting phoenixthrush aniworld downloader are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

phoenixthrush / AniWorld Downloader
0 < 5.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/phoenixthrush/AniWorld-Downloader/issues/334 github.com: https://github.com/phoenixthrush/AniWorld-Downloader/commit/3c070bd10665377308a3092e11933681c18a5fd1 github.com: https://github.com/phoenixthrush/AniWorld-Downloader/releases/tag/v.5.3.0 hackmd.io: https://hackmd.io/@haind/aniworld-login-brute-force github.com: https://github.com/phoenixthrush/AniWorld-Downloader/blob/bb13599d17937fdb4df2df699024bc233f0656f2/src/aniworld/web/auth.py#L239-L256 vulncheck.com: https://www.vulncheck.com/advisories/aniworld-downloader-before-5.3.0-webui-login-brute-force-via-login

Credits

SiroxCW HaiND from the Post and Telecommunication Institute of Technology