CVE-2026-64677 Details
Description
Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or malicious websites combined with an origin-check bypass, to read local files through directory traversal. This issue is fixed in version 25.09.3.
A directory traversal vulnerability has been identified in Anki's local HTTP server, prior to version 25.09.3. This issue allows scripts from shared decks, or those served from malicious websites that can bypass origin checks, to read local files by exploiting inadequate restrictions on media and data path requests. The vulnerability arises from the server's failure to properly validate requested paths, enabling unauthorized access to the file system.
Users can upgrade to Anki version 25.09.3 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ankitects/anki/commit/f4692e54a4fafc89528afab1983f0b98d593023f | [email protected] | Source CodeVendor |
| https://github.com/ankitects/anki/security/advisories/GHSA-78wr-2gg2-4hqg | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Anki | <= 25.09.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 8, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |
Volerion