CVE-2026-59153: Anki's local HTTP server does not sufficiently validate requests
Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ankito a version that resolves this vulnerability.Fixed in 25.09.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59153?
CVE-2026-59153 has a risk score of 35.
How do I fix CVE-2026-59153?
To fix CVE-2026-59153, update Anki to version 25.09.3 or later.
What is the impact of CVE-2026-59153?
CVE-2026-59153 allows a malicious website to potentially trigger unvalidated requests through Anki's local HTTP server.
Which versions of Anki are affected by CVE-2026-59153?
CVE-2026-59153 affects versions of Anki prior to 25.09.3.
How does CVE-2026-59153 relate to request validation?
CVE-2026-59153 highlights insufficient request validation in Anki's local HTTP server.