PT-2026-56267 · Anki · Anki

·

CVE-2026-59153

·

Published

2026-06-19

·

Updated

2026-07-23

CVSS v4.0

2.1

Low

VectorAV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Anki versions prior to 25.09.3
Description Anki launches a local HTTP server to serve media files and web pages for its interface. The server does not sufficiently block requests from other origins, allowing a malicious website to trigger side-effecting requests to the local server. The severity of this issue depends on the Private Network Access protections implemented by the browser.
Recommendations Update to version 25.09.3.

Exploit

Fix

Origin Validation Error

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59153
GHSA-869J-R97X-HX2G
PYSEC-2026-3459

Affected Products

Anki