Vulnerability Report: GO-2025-3424
- CVE-2025-24369
- Affects: github.com/Xe/x
- Published: Jan 29, 2025
- Unreviewed
Anubis has a bot protection bypass when a sophisticated attacker asks to pass a challenge of difficulty 0 in github.com/Xe/x. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/Xe/x before v1.11.0-37-gd98d70a.
For detailed information about this vulnerability, visit https://nvd.nist.gov/vuln/detail/CVE-2025-24369.
Affected Modules
-
PathGo VersionsCustom Versions*
-
all versions, no known fixedbefore 1.11.0-37-gd98d70a
*Custom versions, which can't be mapped automatically to standard Go module versions, are ignored by govulncheck. (See this note on versions for more details.)
Aliases
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-24369
- https://github.com/Xe/x/commit/7bd7b209f4f1b897de85ec8973458dc8be606a8b
- https://github.com/Xe/x/commit/e09d0226a628f04b1d80fd83bee777894a45cd02
- https://github.com/Xe/x/security/advisories/GHSA-56w8-8ppj-2p4f
- https://xeiaso.net/notes/2025/GHSA-56w8-8ppj-2p4f
- https://vuln.go.dev/ID/GO-2025-3424.json