Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59153

Опубликовано: 07 июл. 2026
Источник: nvd
EPSS Низкий

Описание

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.

EPSS

Процентиль: 8%
0.00179
Низкий

Дефекты

CWE-346

Связанные уязвимости

ubuntu
около 1 месяца назад

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.

debian
около 1 месяца назад

Anki is a program for creating and reviewing flashcards. Prior to 25.0 ...

github
около 2 месяцев назад

Anki's local HTTP server does not sufficiently validate requests

EPSS

Процентиль: 8%
0.00179
Низкий

Дефекты

CWE-346