Anki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests.
The severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses:
Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151.
The issue was fixed as of Anki 25.09.3
{
"cwe_ids": [
"CWE-22",
"CWE-346"
],
"github_reviewed": true,
"github_reviewed_at": "2026-06-19T22:10:57Z",
"nvd_published_at": "2026-07-07T22:16:54Z",
"severity": "HIGH"
}