Path traversal in Anki - CVE-2026-58266
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in the internal Anki API when processing requests from scripts included via iframes in the editor. A remote attacker can trick the victim into importing an untrusted .apkg and viewing a card with an embedded iframe to disclose sensitive information.
User interaction is required to import an untrusted .apkg and view a card with an embedded iframe.