
🃏 Anki vulnerable to local file theft CVE-2026-64677 affects Anki before 25.09.3. Weak path restrictions in its local HTTP server can allow malicious deck content—or websites combined with an origin bypass—to read local files through directory traversal. ✅ Fixed: 25.09.3 🔎 Source: Tenable / GitHub Advisory #Anki #PathTraversal #CyberSecurity #CVE
Post summary
The tweet reports CVE‑2026‑64677 as a path‑traversal flaw in Anki’s local HTTP server, notes that version 25.09.3 fixes it, and cites Tenable/GitHub Advisory sources.
