CVE-2026-64677EPSS p62.1%
CVE-2026-64677CVE-2026-64677
Description
Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or malicious websites combined with an origin-check bypass, to read local files through directory traversal. This issue is fixed in version 25.09.3.
Scoring
| EPSS | 1.02% probability of exploitation · percentile 62.1% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-16 |