SB20260917261 - Cross-site scripting in Anki
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the editor.
The vulnerability exists due to improper neutralization of input during web page generation in the CSV import feature when importing a malicious CSV file with HTML fields allowed. A remote attacker can craft a CSV file containing embedded JavaScript to execute arbitrary JavaScript in the editor.
The imported note must be viewed in the editor for the script to execute.
Remediation
Install update from vendor's website.