Path traversal in Anki - CVE-2026-64677
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in the local HTTP server endpoints when handling crafted requests for media files or web pages. A remote attacker can send a specially crafted request to disclose sensitive information.
Exploitation from a website requires another vulnerability that permits access to the local server due to insufficient origin checks, while scripts in shared decks can exploit the issue directly.