GHSA-cf57-c578-7jvv

    Dashboard / Vulnerabilities / GHSA-cf57-c578-7jvv

    GHSA-cf57-c578-7jvv

    Published: 30 Oct 2025Last Modified: 15 Nov 2025

    Summary: Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode

    Details: ### Summary When using subrequest authentication, Anubis did not perform validation of the redirect URL and redirects user to any URL scheme. While most modern browsers do not allow a redirect to `javascript:` URLs, it could still trigger dangerous behavior in some cases. `GET https://example.com/.within.website/?redir=javascript:alert()` responds with `Location: javascript:alert()`. ### Impact Anybody with a subrequest authentication seems affected. Using `javascript:` URLs will probably be blocked by most modern browsers, but using custom protocols for third-party applications might still trigger dangerous operations. ### Note This was originally reported by @mbiesiad against Weblate.

    Affected packages

    Package

    Name: github.com/TecharoHQ/anubis

    Purl: pkg:golang/github.com/TecharoHQ/anubis

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.23.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-cf57-c578-7jvv | CVE-DB