Cross-site scripting in Anki - #VU150786
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform privileged desktop API operations.
The vulnerability exists due to improper neutralization of input during web page generation in the image-occlusion document when rendering imported note HTML. A remote attacker can provide crafted note HTML that is opened in the editor to perform privileged desktop API operations.
Exploitation requires a referenced note with a supported image whose identifier survives import remapping.