DEBIAN-CVE-2026-58266

Source
https://security-tracker.debian.org/tracker/CVE-2026-58266
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-58266.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-58266
Upstream
Withdrawn
2026-07-11T02:00:41Z
Published
2026-07-07T22:16:54Z
Modified
2026-07-11T02:00:41Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Anki is a program for creating and reviewing flashcards. Prior to 25.09.4, Anki's webview-based pages communicate with the Rust backend using an internal localhost API, and user scripts included via iframes in the editor can access this API despite protections intended to block reviewer and editor scripts. A malicious imported card package with an embedded iframe can use exposed API methods such as getImageForOcclusion to read arbitrary files accessible to the Anki process and exfiltrate them over the network. This issue is fixed in version 25.09.4.

References

Affected packages

Debian:11 / anki

Package

Name
anki
Purl
pkg:deb/debian/anki?arch=source&distro=bullseye

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.1.15+dfsg-3
2.1.15+dfsg-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-58266.json"