CVE-2026-108580
AniWorld Downloader before 5.3.0 WebUI Login Brute Force via /login
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
AniWorld Downloader before 5.3.0 contains an improper restriction of authentication attempts vulnerability in the WebUI /login POST handler that allows unauthenticated attackers to guess passwords without throttling. Attackers can enumerate usernames through verify_user response timing and brute-force passwords on exposed WebUI instances to take over accounts.
| CWE | CWE-307 |
| Vendor | phoenixthrush |
| Product | aniworld downloader |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for phoenixthrush aniworld downloader
Be the first to know when new medium vulnerabilities affecting phoenixthrush aniworld downloader are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
phoenixthrush / AniWorld Downloader
0 < 5.3.0
References
github.com: https://github.com/phoenixthrush/AniWorld-Downloader/issues/334 github.com: https://github.com/phoenixthrush/AniWorld-Downloader/commit/3c070bd10665377308a3092e11933681c18a5fd1 github.com: https://github.com/phoenixthrush/AniWorld-Downloader/releases/tag/v.5.3.0 hackmd.io: https://hackmd.io/@haind/aniworld-login-brute-force github.com: https://github.com/phoenixthrush/AniWorld-Downloader/blob/bb13599d17937fdb4df2df699024bc233f0656f2/src/aniworld/web/auth.py#L239-L256 vulncheck.com: https://www.vulncheck.com/advisories/aniworld-downloader-before-5.3.0-webui-login-brute-force-via-login
Credits
SiroxCW HaiND from the Post and Telecommunication Institute of Technology