SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-58266

MEDIUM · CVSS 6.5 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

Anki's webview-based pages prior to version 25.09.4 are vulnerable due to an internal localhost API that can be accessed by user scripts included via iframes, allowing potential exploitation through malicious card packages. This vulnerability enables attackers to read arbitrary files from the Anki process and exfiltrate sensitive data over the network. Users and administrators of Anki should prioritize upgrading to version 25.09.4 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-58266
Severity
MEDIUM
CVSS
6.5
EPSS
0.17%

Original NVD Description

Anki is a program for creating and reviewing flashcards. Prior to 25.09.4, Anki's webview-based pages communicate with the Rust backend using an internal localhost API, and user scripts included via iframes in the editor can access this API despite protections intended to block reviewer and editor scripts. A malicious imported card package with an embedded iframe can use exposed API methods such as getImageForOcclusion to read arbitrary files accessible to the Anki process and exfiltrate them over the network. This issue is fixed in version 25.09.4.