CVE-2025-64716
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-13

Last updated on: 2025-11-13

Assigner: GitHub, Inc.

Description
Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. Prior to version 1.23.0, when using subrequest authentication, Anubis did not perform validation of the redirect URL and redirects user to any URL scheme. While most modern browsers do not allow a redirect to `javascript:` URLs, it could still trigger dangerous behavior in some cases. Anybody with a subrequest authentication may be affected. Version 1.23.0 contains a fix for the issue.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-13
Last Modified
2025-11-13
Generated
2026-05-07
AI Q&A
2025-11-13
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
anubis anubis *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in Anubis Web AI Firewall Utility occurs because, prior to version 1.23.0, when using subrequest authentication, the software did not validate the redirect URL properly. This allowed redirects to any URL scheme, including potentially dangerous ones like 'javascript:'. Although most modern browsers block such redirects, in some cases this could still trigger harmful behavior. The issue was fixed in version 1.23.0.


How can this vulnerability impact me? :

If you use Anubis with subrequest authentication, this vulnerability could allow an attacker to redirect users to malicious URLs, potentially leading to security risks such as executing harmful scripts or phishing attacks. This could compromise user security and trust.


What immediate steps should I take to mitigate this vulnerability?

Upgrade Anubis to version 1.23.0 or later, as this version contains a fix that properly validates redirect URLs in subrequest authentication to prevent unsafe redirects.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart