Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.
CVSS
No CVSS.
References
Configurations
No configuration.
History
07 Jul 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-07 22:16
Updated : 2026-07-08 15:28
NVD link : CVE-2026-59153
Mitre link : CVE-2026-59153
CVE.ORG link : CVE-2026-59153
JSON object : View
Products Affected
No product.
CWE
CWE-346
Origin Validation Error
