{"id":"CVE-2026-59153","aliases":["GHSA-869j-r97x-hx2g"],"title":"Anki's local HTTP server does not sufficiently validate requests","summary":"Anki's local HTTP server does not sufficiently validate requests","severity":"high","vendor":"aqt","product":"aqt","ecosystem":"pip","affected":["aqt < 25.9.3"],"patched":["aqt 25.9.3"],"published":"2026-06-19","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-869j-r97x-hx2g","references":[{"url":"https://github.com/ankitects/anki/security/advisories/GHSA-869j-r97x-hx2g"},{"url":"https://github.com/ankitects/anki"},{"url":"https://x.com/taviso/status/2051310678800253318"}],"tags":["osv","pip"],"epss":0.00264,"epssPercentile":0.18643,"ingestedAt":"2026-07-08T18:25:47.309Z","slug":"CVE-2026-59153","body":"## Overview\n\n## Summary\n\nAnki launches a local HTTP server to serve media files and web pages for parts of its interface. The server fails to validate requests in the following ways:\n1. No sufficient validation of the Origin header.\n2. Some endpoints are vulnerable to path traversal attacks.\n\nThis allows malicious websites to exfiltrate local files given a known path.\n\n## Browser impact\n\nThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses:\n\nChrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt.\nSafari: Hasn't implemented PNA yet, though macOS has some OS-level protections.\nFirefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151.\n\n## Patches\n\nThe issue was fixed as of Anki 25.09.3\n\n## Affected packages\n\n- `aqt < 25.9.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `aqt 25.9.3`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}