Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Bankde

#44182of 56,326
6.5Total CVSS
Vulnerabilities · 1
PT-2026-56266
6.5
2026-06-19
Anki · Anki · CVE-2026-58266
**Name of the Vulnerable Software and Affected Versions** Anki versions prior to 25.09.4 **Description** Webview-based pages communicate with the Rust backend via an internal localhost API. User scripts included through iframes in the editor can bypass protections to access this API. A malicious imported card package containing an embedded iframe can utilize the `getImageForOcclusion()` function to read arbitrary files accessible to the process and exfiltrate them over the network. **Recommendations** Update to version 25.09.4.