VDB
Sign up
—

PYSEC-2026-3459

Anki's local HTTP server does not sufficiently validate requests

Quick fix

PYSEC-2026-3459 — aqt: upgrade to the fixed version with the command below.

pip install --upgrade 'aqt>=25.9.3'

Details

## Summary

Anki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests.

## Browser impact

The severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses:

Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt. Safari: Hasn't implemented PNA yet, though macOS has some OS-level protections. Firefox: Most vulnerable — hasn't implemented PNA yet, though it's reportedly planned for Firefox 151.

## Patches

The issue was fixed as of Anki 25.09.3

### References

https://x.com/taviso/status/2051310678800253318

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/aqt
Introduced in: 0Fixed in: 25.9.3
Fixpip install --upgrade 'aqt>=25.9.3'

References