CVE-2026-64677: Anki's local HTTP server is vulnerable to directory traversal attacks
Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or malicious websites combined with an origin-check bypass, to read local files through directory traversal. This issue is fixed in version 25.09.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Anki local HTTP serverto a version that resolves this vulnerability.Fixed in 25.09.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64677?
The severity of CVE-2026-64677 is rated as risk 51.
How do I fix CVE-2026-64677?
To fix CVE-2026-64677, update Anki to version 25.09.3 or later.
What type of vulnerability is CVE-2026-64677?
CVE-2026-64677 is a path traversal vulnerability affecting Anki's local HTTP server.
What can attackers achieve with CVE-2026-64677?
Attackers can exploit CVE-2026-64677 to read local files through directory traversal techniques.
Who is affected by CVE-2026-64677?
Users of Anki versions prior to 25.09.3 are affected by CVE-2026-64677.