PT-2025-30951 · Anubis+1 · Anubis+1

Xe

·

Published

2025-07-26

·

Updated

2025-07-29

·

CVE-2025-54414

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Anubis versions 1.21.2 and below
Description Anubis is a Web AI Firewall Utility designed to protect upstream resources from scraper bots. Attackers can craft malicious pass-challenge pages that cause a user to execute arbitrary JavaScript code or trigger other nonstandard schemes. The incomplete fix was initially tagged in version 1.21.2, but the release was aborted. The issue is addressed in version 1.21.3.
Recommendations Block any requests to the /api/pass-challenge route with the redir parameter set to anything that doesn't start with the URL scheme http, https, or no scheme (local path redirect). Update to version 1.21.3.

Exploit

Fix

Open Redirect

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2025-9752
CVE-2025-54414
GHSA-JHJJ-2G64-PX7C

Affected Products

Alt Linux
Anubis