CVE-2026-59153 LOW

CVE-2026-59153: Anki's local HTTP server does not sufficiently validate requests

Vendor Ankitects
Product anki
Weakness CWE-346 · Origin validation
Published July 7, 2026
Last update July 7, 2026

CVSS base score

2.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.

Key dates

02Disclosure timeline

July 7, 2026 CVE published