CVE-2025-64716

MEDIUM

Techarohq Anubis < 1.23.0 - XSS

Title source: rule
STIX 2.1

Description

Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. Prior to version 1.23.0, when using subrequest authentication, Anubis did not perform validation of the redirect URL and redirects user to any URL scheme. While most modern browsers do not allow a redirect to `javascript:` URLs, it could still trigger dangerous behavior in some cases. Anybody with a subrequest authentication may be affected. Version 1.23.0 contains a fix for the issue.

Scores

CVSS v4 5.1
EPSS 0.0008
EPSS Percentile 23.2%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601 CWE-79
Status published
Products (2)
TecharoHQ/anubis 0 - 1.23.0Go
TecharoHQ/anubis < 1.23.0
Published Nov 13, 2025
Tracked Since Feb 18, 2026