aqt vulnerabilities
CVEs whose affected-version data names the aqt package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-58266Medium· 6.5Anki: User scripts in iframes have access to the internal Anki API
Anki: User scripts in iframes have access to the internal Anki API
▾ Sunlitaqt · aqtEPSS 0.22%via OSV
CVE-2026-59153HighAnki's local HTTP server does not sufficiently validate requests
Anki's local HTTP server does not sufficiently validate requests
▾ Twilightaqt · aqtEPSS 0.26%via OSV
GHSA-cw6h-ffmh-x6vhMedium· 6.5Anki: User scripts in iframes have access to the internal Anki API
Anki: User scripts in iframes have access to the internal Anki API
▾ Sunlitaqt · aqtvia GHSA
GHSA-869j-r97x-hx2gHighAnki's local HTTP server does not sufficiently validate requests
Anki's local HTTP server does not sufficiently validate requests
▾ Twilightaqt · aqtvia GHSA