Browse all 11 CVE security advisories affecting Ankitects. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Ankitects develops Anki, a spaced repetition flashcard application used for memorization. Historically, the application has been vulnerable to multiple security issues including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. These vulnerabilities often stem from improper input validation and insecure data handling. While no major public security incidents have been widely reported, the presence of eight CVEs indicates a history of security flaws that have required patches. The application's nature as a client-side tool with local data storage limits the attack surface compared to networked applications, but vulnerabilities in its web components and integration points remain a concern for users.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-64677 | Anki's local HTTP server is vulnerable to directory traversal attacks — anki CWE-22 | 5.9 | Medium | 2026-08-06 |
| CVE-2026-58266 | Anki: User scripts in iframes have access to the internal Anki API — anki CWE-346 | 6.5 | Medium | 2026-07-07 |
| CVE-2026-59153 | Anki's local HTTP server does not sufficiently validate requests — anki CWE-346 | - | - | 2026-07-07 |
| CVE-2025-62185 | Ankitects Anki 代码问题漏洞 — Anki CWE-427 | 6.7 | Medium | 2025-10-07 |
| CVE-2025-62186 | Ankitects Anki 安全漏洞 — Anki CWE-829 | 6.7 | Medium | 2025-10-07 |
| CVE-2025-62187 | Ankitects Anki 安全漏洞 — Anki CWE-23 | 2.9 | Low | 2025-10-07 |
| CVE-2025-43703 | Anki 安全漏洞 — Anki CWE-830 | 6.1 | Medium | 2025-04-16 |
| CVE-2024-29073 | Ankitects Anki 安全漏洞 — Anki CWE-829 | 5.3 | Medium | 2024-07-22 |
| CVE-2024-26020 | Ankitects Anki 注入漏洞 — Anki CWE-74 | 9.6 | Critical | 2024-07-22 |
| CVE-2024-32152 | Ankitects Anki 安全漏洞 — Anki CWE-184 | 3.1 | Low | 2024-07-22 |
| CVE-2024-32484 | Ankitects Anki 安全漏洞 — Anki CWE-80 | 7.4 | High | 2024-07-22 |
This page lists every published CVE security advisory associated with Ankitects. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.