Impact
The Anubis Web AI Firewall Utility mistakenly accepts the client-controlled X-Original-URI header before evaluating the request’s URL path. By sending a crafted X-Original-URI that matches allow rules such as the default ^\/\.well-known\/.*$ pattern, an attacker can avoid the firewall’s challenge and gain access to protected resources. This flaw represents an authorization weakness (CWE‑284) and does not permit code execution but allows the bypass of intended protective measures.
Affected Systems
The flaw affects TecharoHQ Anubis releases from version 1.22.0 up to, but not including, 1.26.0-pre1. Users running any of those versions are susceptible; the issue is fixed in the 1.26.0-pre1 release and later.
Risk and Exploitability
The CVSS score of 5.8 indicates moderate severity, and the EPSS score of less than 1% suggests a low exploitation probability in the general population. Any remote HTTP client capable of setting the X-Original-URI header can trigger the bypass without authentication or elevated privileges, making the attack surface wide. Although not currently listed in CISA KEV, the potential to grant unauthorized access to sensitive services means the risk remains significant for environments that rely on Anubis to block scraper bots.
OpenCVE Enrichment