{"id":"PYSEC-2026-3459","summary":"Anki's local HTTP server does not sufficiently validate requests","details":"## Summary\n\nAnki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests.\n\n## Browser impact\n\nThe severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses:\n\nChrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt.\nSafari: Hasn't implemented PNA yet, though macOS has some OS-level protections.\nFirefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151.\n\n## Patches\n\nThe issue was fixed as of Anki 25.09.3\n\n### References\n\nhttps://x.com/taviso/status/2051310678800253318","aliases":["CVE-2026-59153","GHSA-869j-r97x-hx2g"],"modified":"2026-07-23T15:00:10.895986265Z","published":"2026-07-23T11:41:44.710117Z","references":[{"type":"WEB","url":"https://github.com/ankitects/anki/security/advisories/GHSA-869j-r97x-hx2g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59153"},{"type":"WEB","url":"https://github.com/ankitects/anki/commit/858e5689d0e4fd24f74856c7e8f245412694a219"},{"type":"PACKAGE","url":"https://github.com/ankitects/anki"},{"type":"WEB","url":"https://github.com/ankitects/anki/releases/tag/25.09.3"},{"type":"WEB","url":"https://x.com/taviso/status/2051310678800253318"},{"type":"PACKAGE","url":"https://pypi.org/project/aqt"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-869j-r97x-hx2g"}],"affected":[{"package":{"name":"aqt","ecosystem":"PyPI","purl":"pkg:pypi/aqt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"25.9.3"}]}],"versions":["2.1.24","2.1.25","2.1.26","2.1.28","2.1.29","2.1.30","2.1.31","2.1.32","2.1.33","2.1.34","2.1.35","2.1.36","2.1.37","2.1.37rc1","2.1.38","2.1.38b1","2.1.38b2","2.1.38b3","2.1.38b4","2.1.39","2.1.39b1","2.1.39b2","2.1.40","2.1.41","2.1.41b1","2.1.41b2","2.1.41b3","2.1.41b4","2.1.41b5","2.1.41b6","2.1.41b7","2.1.42","2.1.43","2.1.43b1","2.1.44","2.1.44b1","2.1.45","2.1.45a1","2.1.45a2","2.1.45a3","2.1.45a4","2.1.45b1","2.1.45b2","2.1.45b3","2.1.45b4","2.1.45b5","2.1.45b6","2.1.45rc1","2.1.45rc2","2.1.46","2.1.46rc1","2.1.47","2.1.47rc1","2.1.47rc2","2.1.48","2.1.48rc1","2.1.48rc2","2.1.49","2.1.50","2.1.50b1","2.1.50b2","2.1.50b3","2.1.50b4","2.1.50b5","2.1.50b6","2.1.50b7","2.1.50b8","2.1.50b9","2.1.50rc1","2.1.50rc2","2.1.50rc3","2.1.50rc4","2.1.51","2.1.51rc1","2.1.51rc2","2.1.52","2.1.52rc1","2.1.52rc2","2.1.52rc3","2.1.53","2.1.53rc1","2.1.53rc2","2.1.54","2.1.54rc1","2.1.54rc2","2.1.54rc3","2.1.55","2.1.55b1","2.1.55b2","2.1.55b3","2.1.55b4","2.1.55b6","2.1.55b7","2.1.55rc1","2.1.55rc2","2.1.56","2.1.56rc1","2.1.57","2.1.57b1","2.1.57rc1","2.1.58","2.1.59","2.1.60","2.1.61","2.1.61b1","2.1.61b2","2.1.62","2.1.62b1","2.1.62rc1","2.1.63","2.1.64","2.1.65","2.1.66","2.1.66b1","2.1.66rc1","23.10","23.10.1","23.10.1rc1","23.10.1rc2","23.10b1","23.10b2","23.10b3","23.10b4","23.10b5","23.10b6","23.10rc1","23.10rc2","23.10rc3","23.12","23.12.1","23.12b1","23.12b2","23.12b3","23.12rc1","24.10b1","24.10b2","24.10b3","24.10b4","24.10rc1","24.10rc2","24.11","24.11rc1","24.11rc2","24.4","24.4.1","24.4rc1","24.4rc2","24.6","24.6.1","24.6.2","24.6.3","25.1b1","25.1rc1","25.2","25.2.1","25.2.2","25.2.3","25.2.4","25.2.5","25.2.6","25.2.7","25.2rc1","25.5b1","25.5b2","25.6b1","25.6b2","25.6b3","25.6b4","25.6b5","25.6b6","25.6b7","25.7","25.7.1","25.7.2","25.7.3","25.7.3rc1","25.7.4","25.7.5","25.8b1","25.8b2","25.8b3","25.8b4","25.8b5","25.9","25.9.1","25.9.2","25.9rc1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/aqt/PYSEC-2026-3459.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}