Vulnerability Description
Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.
Related Weaknesses (CWE)
References
- https://github.com/ankitects/anki/commit/858e5689d0e4fd24f74856c7e8f245412694a21
- https://github.com/ankitects/anki/releases/tag/25.09.3
- https://github.com/ankitects/anki/security/advisories/GHSA-869j-r97x-hx2g
- https://x.com/taviso/status/2051310678800253318
FAQ
What is CVE-2026-59153?
CVE-2026-59153 is a documented vulnerability. Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other orig...
How severe is CVE-2026-59153?
CVSS scoring is not yet available for CVE-2026-59153. Check NVD for updates.
Is there a patch for CVE-2026-59153?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.