{"id":"CVE-2026-59153","aliases":["GHSA-869j-r97x-hx2g","PYSEC-2026-3459"],"url":"https://o3.security/vulnerability/CVE-2026-59153","summary":"Anki's local HTTP server does not sufficiently validate requests","details":"Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.","published":"2026-07-07T21:11:01.808Z","modified":"2026-08-12T03:51:15.887456163Z","cvss":null,"epss":{"score":0.00264,"percentile":0.18181,"asOf":"2026-09-07"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"aqt","fixedVersion":"25.9.3"}],"fix":{"url":"https://github.com/ankitects/anki/commit/858e5689d0e4fd24f74856c7e8f245412694a219","label":"ankitects/anki@858e568"},"references":[{"type":"WEB","url":"https://github.com/ankitects/anki/releases/tag/25.09.3"},{"type":"WEB","url":"https://x.com/taviso/status/2051310678800253318"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59153.json"},{"type":"ADVISORY","url":"https://github.com/ankitects/anki/security/advisories/GHSA-869j-r97x-hx2g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59153"},{"type":"FIX","url":"https://github.com/ankitects/anki/commit/858e5689d0e4fd24f74856c7e8f245412694a219"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:15.887456163Z"}}