Executive brief
Anki is a widely-used flashcard learning application that runs a local web server to display study materials and media. Prior to version 25.09.3, attackers could exploit insufficient path validation to read arbitrary files from a user's computer—either through malicious websites combined with a separate origin-check bypass, or through scripts embedded in downloaded flashcard decks. This could expose sensitive personal data, documents, or system files.
Technical details
The vulnerability is a directory traversal (path traversal) issue in Anki's local HTTP server endpoints that serve media files and built-in data. The vulnerable component did not adequately constrain or validate requested file paths, allowing an attacker to use sequences like "../" to navigate outside intended directories. The attack can be triggered from shared deck scripts (which run in the same origin as the server) or from external websites if combined with an origin-check bypass. An attacker can read any file accessible to the Anki process. The fix, applied in version 25.09.3, implements proper path validation (ensure_safe_path) and applies it consistently across both media and built-in data endpoints.
Affected products
- Ankitects Anki prior to 25.09.3
Timeline
- 2026-07-27: disclosed
- 2026-09-03: patched: Fixed in version 25.09.3
- 2026-08-06: advisory