PT-2025-45700 · Go · Github.Com/Techarohq/Anubis
Published
2025-10-30
·
Updated
2025-10-30
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N |
Summary
When using subrequest authentication, Anubis did not perform validation of the redirect URL and redirects user to any URL scheme. While most modern browsers do not allow a redirect to
javascript: URLs, it could still trigger dangerous behavior in some cases.GET https://example.com/.within.website/?redir=javascript:alert() responds with Location: javascript:alert().Impact
Anybody with a subrequest authentication seems affected. Using
javascript: URLs will probably be blocked by most modern browsers, but using custom protocols for third-party applications might still trigger dangerous operations.Note
This was originally reported by @mbiesiad against Weblate.
Fix
XSS
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Github.Com/Techarohq/Anubis