Path traversal in Anki - CVE-2026-64677

 

Path traversal in Anki - CVE-2026-64677

Published: July 28, 2026


Vulnerability identifier: #VU139909
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64677
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to path traversal in the local HTTP server endpoints when handling crafted requests for media files or web pages. A remote attacker can send a specially crafted request to disclose sensitive information.

Exploitation from a website requires another vulnerability that permits access to the local server due to insufficient origin checks, while scripts in shared decks can exploit the issue directly.


Affected software

Anki

How to mitigate CVE-2026-64677

Install security update from vendor's website.

Anki - update to 25.09.3

External References

Related Security Bulletins