SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-59153

LOW · CVSS 2.1 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

Anki versions prior to 25.09.3 are vulnerable due to insufficient blocking of cross-origin requests to its local HTTP server, which serves media files and web pages. This flaw could allow a malicious website to make unauthorized requests to the local server, potentially leading to data exposure or manipulation, with the impact severity varying by browser configuration. Users and organizations utilizing Anki for educational purposes should prioritize updating to the latest version to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59153
Severity
LOW
CVSS
2.1
EPSS
0.18%

Original NVD Description

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.