CVE-2025-64716 - CVE House
Back to Database
Status published Medium CVE-2025-64716

Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode

Vulnerability Description

Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. Prior to version 1.23.0, when using subrequest authentication, Anubis did not perform validation of the redirect URL and redirects user to any URL scheme. While most modern browsers do not allow a redirect to `javascript:` URLs, it could still trigger dangerous behavior in some cases. Anybody with a subrequest authentication may be affected. Version 1.23.0 contains a fix for the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64716

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

anubis
Vulnerable Versions:
< 1.23.0

Timeline

Official Publish: November 13th, 2025
Last Modified: November 13th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)