CVE-2026-64677
Anki's local HTTP server is vulnerable to directory traversal attacks
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or malicious websites combined with an origin-check bypass, to read local files through directory traversal. This issue is fixed in version 25.09.3.
| CWE | CWE-22 |
| Vendor | ankitects |
| Product | anki |
| Published | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for ankitects anki
Be the first to know when new unknown vulnerabilities affecting ankitects anki are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
ankitects / anki
>= 25.09.3