CVE-2026-64677

NameCVE-2026-64677
DescriptionAnki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or malicious websites combined with an origin-check bypass, to read local files through directory traversal. This issue is fixed in version 25.09.3.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ankisourcebullseye(not affected)
ankisource(unstable)(unfixed)

Notes

[bullseye] - anki <not-affected> (Vulnerable local-server API absent in 2.1.15)

Search for package or bug name: Reporting problems