Cross-site scripting in Anki - #VU150788
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the editor.
The vulnerability exists due to improper neutralization of input during web page generation in the CSV import feature when importing a malicious CSV file with HTML fields allowed. A remote attacker can craft a CSV file containing embedded JavaScript to execute arbitrary JavaScript in the editor.
The imported note must be viewed in the editor for the script to execute.