CVE-2026-59153 Details
Description
Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.
A vulnerability exists in Anki, a flashcard creation and review program, in versions prior to 25.09.3. The issue arises because Anki launches a local HTTP server to serve media files and web pages for its interface. However, the server's origin validation was insufficient, allowing requests from other origins to bypass restrictions. This flaw could enable a malicious website to initiate side-effecting requests to the local server. The severity of this vulnerability varies by browser, with Firefox users being the most affected. The issue has been resolved in Anki version 25.09.3.
Users can upgrade to Anki version 25.09.3 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 7, 2026CISA-ADP
Assessed Jul 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ankitects/anki/commit/858e5689d0e4fd24f74856c7e8f245412694a219 | [email protected] | Source CodeVendor |
| https://github.com/ankitects/anki/releases/tag/25.09.3 | [email protected] | Release NotesVendor |
| https://github.com/ankitects/anki/security/advisories/GHSA-869j-r97x-hx2g | [email protected] | AdvisoryRemedyVendor |
| https://x.com/taviso/status/2051310678800253318 | [email protected] | Media Coverage |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-346 | Origin Validation Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Anki | <= 25.09.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | CVE Modified | CISA-ADP |
| Jul 7, 2026 | New CVE Received | [email protected] |
Volerion