VYPR
Medium severityNVD Advisory· Published Aug 6, 2026

CVE-2026-64677

CVE-2026-64677

Description

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or malicious websites combined with an origin-check bypass, to read local files through directory traversal. This issue is fixed in version 25.09.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Ankitects/Ankireferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <25.09.3

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.