PT-2025-30951 · Anubis+1 · Anubis+1
Xe
·
Published
2025-07-26
·
Updated
2025-07-29
·
CVE-2025-54414
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Anubis versions 1.21.2 and below
Description
Anubis is a Web AI Firewall Utility designed to protect upstream resources from scraper bots. Attackers can craft malicious pass-challenge pages that cause a user to execute arbitrary JavaScript code or trigger other nonstandard schemes. The incomplete fix was initially tagged in version 1.21.2, but the release was aborted. The issue is addressed in version 1.21.3.
Recommendations
Block any requests to the
/api/pass-challenge route with the redir parameter set to anything that doesn't start with the URL scheme http, https, or no scheme (local path redirect).
Update to version 1.21.3.Exploit
Fix
Open Redirect
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Anubis