CVE-2026-59153

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.
CVSS

No CVSS.

Configurations

No configuration.

History

07 Jul 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-07 22:16

Updated : 2026-07-08 15:28


NVD link : CVE-2026-59153

Mitre link : CVE-2026-59153

CVE.ORG link : CVE-2026-59153


JSON object : View

Products Affected

No product.

CWE
CWE-346

Origin Validation Error