Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59153

Опубликовано: 07 июл. 2026
Источник: debian
EPSS Низкий

Описание

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ankiremovedpackage
ankinot-affectedbullseyepackage

Примечания

  • https://github.com/ankitects/anki/security/advisories/GHSA-869j-r97x-hx2g

  • Fixed by: https://github.com/ankitects/anki/commit/858e5689d0e4fd24f74856c7e8f245412694a219 (25.09.3)

EPSS

Процентиль: 8%
0.00179
Низкий

Связанные уязвимости

ubuntu
30 дней назад

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.

nvd
30 дней назад

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.

github
около 2 месяцев назад

Anki's local HTTP server does not sufficiently validate requests

EPSS

Процентиль: 8%
0.00179
Низкий