aqt
Qt-based desktop GUI for Anki, the spaced repetition flashcard program
Activity
- Latest release
- 23h ago
- Total releases
- 201
- Cadence
- ~4 days
- Last 12 months
- 14
Details
- License
- unknown
- First release
- Apr 27, 2020
| Version | Released | |
|---|---|---|
26.9
minor
|
26.9
minor
Dependencies (17)
+ 9 more |
|
26.9b3
pre
|
26.9b3
pre
Dependencies (17)
+ 9 more |
|
26.9b2
pre
|
26.9b2
pre
Dependencies (17)
+ 9 more |
|
26.9b1
pre
|
26.9b1
pre
Dependencies (17)
+ 9 more |
|
26.8.1
patch
|
26.8.1
patch
Dependencies (17)
+ 9 more |
|
26.8
minor
|
26.8
minor
Dependencies (17)
+ 9 more |
|
26.8b2
pre
|
26.8b2
pre
Dependencies (17)
+ 9 more |
|
26.8b1
pre
|
26.8b1
pre
Dependencies (17)
+ 9 more |
|
25.9.5
patch
|
25.9.5
patch
Dependencies (16)
+ 8 more |
|
26.5
major
|
26.5
major
Dependencies (17)
+ 9 more |
|
26.5b2
pre
|
26.5b2
pre
Dependencies (17)
+ 9 more |
|
26.5b1
pre
|
26.5b1
pre
Dependencies (17)
+ 9 more |
|
25.9.4
patch
|
25.9.4
patch
Dependencies (16)
+ 8 more |
|
25.9.3
patch
1 CVE
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.9.3
patch
Dependencies (16)
+ 8 more |
|
25.9.2
patch
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.9.2
patch
Dependencies (17)
+ 9 more |
|
25.9.1
patch
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.9.1
patch
Dependencies (17)
+ 9 more |
|
25.9
minor
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.9
minor
Dependencies (17)
+ 9 more |
|
25.9rc1
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.9rc1
pre
Dependencies (17)
+ 9 more |
|
25.8b5
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.8b5
pre
Dependencies (17)
+ 9 more |
|
25.8b4
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.8b4
pre
Dependencies (17)
+ 9 more |
|
25.8b3
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.8b3
pre
Dependencies (17)
+ 9 more |
|
25.7.5
patch
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.7.5
patch
Dependencies (17)
+ 9 more |
|
25.7.4
patch
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.7.4
patch
Dependencies (17)
+ 9 more |
|
25.7.3
patch
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.7.3
patch
Dependencies (17)
+ 9 more |
|
25.7.3rc1
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.7.3rc1
pre
Dependencies (17)
+ 9 more |
|
25.8b2
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.8b2
pre
Dependencies (17)
+ 9 more |
|
25.8b1
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.8b1
pre
Dependencies (17)
+ 9 more |
|
25.7.2
patch
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.7.2
patch
Dependencies (17)
+ 9 more |
|
25.7.1
patch
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.7.1
patch
Dependencies (17)
+ 9 more |
|
25.7
minor
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.7
minor
Dependencies (17)
+ 9 more |
|
25.6b7
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.6b7
pre
Dependencies (17)
+ 9 more |
|
25.6b6
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.6b6
pre
Dependencies (17)
+ 9 more |
|
25.6b5
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.6b5
pre
Dependencies (25)
+ 17 more |
|
25.6b4
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.6b4
pre
Dependencies (25)
+ 17 more |
|
25.6b3
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.6b3
pre
Dependencies (25)
+ 17 more |
|
25.6b2
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.6b2
pre
Dependencies (25)
+ 17 more |
|
25.6b1
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.6b1
pre
Dependencies (13)
+ 5 more |
|
25.2.7
patch
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.2.7
patch
Dependencies (13)
+ 5 more |
|
25.2.6
patch
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.2.6
patch
Dependencies (13)
+ 5 more |
|
25.2.5
patch
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.2.5
patch
Dependencies (13)
+ 5 more |
|
25.5b2
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.5b2
pre
Dependencies (13)
+ 5 more |
|
25.5b1
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.5b1
pre
Dependencies (13)
+ 5 more |
|
25.2.4
patch
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.2.4
patch
Dependencies (13)
+ 5 more |
|
25.2.3
patch
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.2.3
patch
Dependencies (13)
+ 5 more |
|
25.2.2
patch
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.2.2
patch
Dependencies (13)
+ 5 more |
|
25.2.1
patch
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.2.1
patch
Dependencies (13)
+ 5 more |
|
25.2
major
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.2
major
Dependencies (13)
+ 5 more |
|
25.2rc1
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.2rc1
pre
Dependencies (13)
+ 5 more |
|
25.1rc1
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.1rc1
pre
Dependencies (13)
+ 5 more |
|
25.1b1
pre
2 CVEs
CVE-2026-59153
PYSEC-2026-3459
GHSA-869j-r97x-hx2g
Jul 23, 2026
Anki's local HTTP server does not sufficiently validate requests
High
Network
Low
None
None
SummaryAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests. Browser impactThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses: Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151. PatchesThe issue was fixed as of Anki 25.09.3 Referenceshttps://x.com/taviso/status/2051310678800253318 Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 175 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9rc1
Fixed in
25.9.3
References
Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-58266
GHSA-cw6h-ffmh-x6vh
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryAnki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts included via iframes in the editor. While overall only a limited set of API methods are exposed, some such as CWE: CWE-22 (Path Traversal) Reporter: Bankde (Eakasit) Affected Products| Ecosystem | Package | Affected Versions |
| --------- | ------- | ----------------- |
| PyPI | ImpactAny desktop Anki user (Windows, macOS, Linux) who imports an untrusted PatchesA patch is available in 25.09.4 Workarounds
References
Affected versions
2.1.24
2.1.25
2.1.26
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
+ 176 more Show less
2.1.37
2.1.37rc1
2.1.38
2.1.38b1
2.1.38b2
2.1.38b3
2.1.38b4
2.1.39
2.1.39b1
2.1.39b2
2.1.40
2.1.41
2.1.41b1
2.1.41b2
2.1.41b3
2.1.41b4
2.1.41b5
2.1.41b6
2.1.41b7
2.1.42
2.1.43
2.1.43b1
2.1.44
2.1.44b1
2.1.45
2.1.45a1
2.1.45a2
2.1.45a3
2.1.45a4
2.1.45b1
2.1.45b2
2.1.45b3
2.1.45b4
2.1.45b5
2.1.45b6
2.1.45rc1
2.1.45rc2
2.1.46
2.1.46rc1
2.1.47
2.1.47rc1
2.1.47rc2
2.1.48
2.1.48rc1
2.1.48rc2
2.1.49
2.1.50
2.1.50b1
2.1.50b2
2.1.50b3
2.1.50b4
2.1.50b5
2.1.50b6
2.1.50b7
2.1.50b8
2.1.50b9
2.1.50rc1
2.1.50rc2
2.1.50rc3
2.1.50rc4
2.1.51
2.1.51rc1
2.1.51rc2
2.1.52
2.1.52rc1
2.1.52rc2
2.1.52rc3
2.1.53
2.1.53rc1
2.1.53rc2
2.1.54
2.1.54rc1
2.1.54rc2
2.1.54rc3
2.1.55
2.1.55b1
2.1.55b2
2.1.55b3
2.1.55b4
2.1.55b6
2.1.55b7
2.1.55rc1
2.1.55rc2
2.1.56
2.1.56rc1
2.1.57
2.1.57b1
2.1.57rc1
2.1.58
2.1.59
2.1.60
2.1.61
2.1.61b1
2.1.61b2
2.1.62
2.1.62b1
2.1.62rc1
2.1.63
2.1.64
2.1.65
2.1.66
2.1.66b1
2.1.66rc1
23.10
23.10.1
23.10.1rc1
23.10.1rc2
23.10b1
23.10b2
23.10b3
23.10b4
23.10b5
23.10b6
23.10rc1
23.10rc2
23.10rc3
23.12
23.12.1
23.12b1
23.12b2
23.12b3
23.12rc1
24.10b1
24.10b2
24.10b3
24.10b4
24.10rc1
24.10rc2
24.11
24.11rc1
24.11rc2
24.4
24.4.1
24.4rc1
24.4rc2
24.6
24.6.1
24.6.2
24.6.3
25.1b1
25.1rc1
25.2
25.2.1
25.2.2
25.2.3
25.2.4
25.2.5
25.2.6
25.2.7
25.2rc1
25.5b1
25.5b2
25.6b1
25.6b2
25.6b3
25.6b4
25.6b5
25.6b6
25.6b7
25.7
25.7.1
25.7.2
25.7.3
25.7.3rc1
25.7.4
25.7.5
25.8b1
25.8b2
25.8b3
25.8b4
25.8b5
25.9
25.9.1
25.9.2
25.9.3
25.9rc1
Fixed in
25.9.4
References Updated Jul 08, 2026 · Source: OSV.dev |
25.1b1
pre
Dependencies (13)
+ 5 more |