Web AI Firewall Utility Anubis Vulnerability Exposes Users to Code Execution Risks
CVE-2025-54414
5.1MEDIUM
What is CVE-2025-54414?
The Anubis Web AI Firewall Utility, designed to safeguard user connections from scraper bots, contains a vulnerability in versions prior to 1.21.3. This flaw allows attackers to craft malicious pass-challenge pages, which can execute arbitrary JavaScript code in the context of the user’s session. Such attacks can compromise sensitive information and disrupt normal function. A workaround involves blocking specific requests to the pass-challenge route with certain parameters. Users are advised to upgrade to version 1.21.3, where this issue has been addressed.
Affected Version(s)
anubis < 1.21.3