GHSA-cf57-c578-7jvv
Dashboard / Vulnerabilities / GHSA-cf57-c578-7jvv
GHSA-cf57-c578-7jvv
Summary: Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode
Details: ### Summary When using subrequest authentication, Anubis did not perform validation of the redirect URL and redirects user to any URL scheme. While most modern browsers do not allow a redirect to `javascript:` URLs, it could still trigger dangerous behavior in some cases. `GET https://example.com/.within.website/?redir=javascript:alert()` responds with `Location: javascript:alert()`. ### Impact Anybody with a subrequest authentication seems affected. Using `javascript:` URLs will probably be blocked by most modern browsers, but using custom protocols for third-party applications might still trigger dangerous operations. ### Note This was originally reported by @mbiesiad against Weblate.
References: https://github.com/TecharoHQ/anubis/security/advisories/GHSA-cf57-c578-7jvv, https://nvd.nist.gov/vuln/detail/CVE-2025-64716, https://github.com/TecharoHQ/anubis/commit/7ed1753fcced351c81961bf520a7bfb2caac6e88, https://github.com/TecharoHQ/anubis, https://pkg.go.dev/vuln/GO-2025-4086
Affected packages
Package
Name: github.com/TecharoHQ/anubis
Purl: pkg:golang/github.com/TecharoHQ/anubis
Affected ranges
Type: SEMVER
Events:
