CyberRota Analysis
AI-GeneratedAnki versions prior to 25.09.3 are vulnerable due to insufficient blocking of cross-origin requests to its local HTTP server, which serves media files and web pages. This flaw could allow a malicious website to make unauthorized requests to the local server, potentially leading to data exposure or manipulation, with the impact severity varying by browser configuration. Users and organizations utilizing Anki for educational purposes should prioritize updating to the latest version to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.