PT-2026-68771 · Anki · Anki

CVE-2026-64677

·

Published

2026-08-06

·

Updated

2026-08-06

CVSS v4.0

5.9

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Anki versions prior to 25.09.3
Description Endpoints in the local HTTP server do not adequately constrain requested media and built-in data paths. This allows scripts served from shared decks, or malicious websites using an origin-check bypass, to read local files via directory traversal, a method used to access files and directories that are stored outside the web root folder.
Recommendations Update to version 25.09.3.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64677
GHSA-78WR-2GG2-4HQG

Affected Products

Anki