Improper access control in Anki - CVE-2026-59153
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to trigger side-effecting requests.
The vulnerability exists due to improper access control in the local HTTP server when handling requests from other origins. A remote attacker can host a malicious website to trigger side-effecting requests.
Browser behavior affects exposure because some browsers do not enforce private network access restrictions for localhost requests.