A vulnerability described as problematic has been identified in AnkiTects Anki up to 25.09.2. The impacted element is an unknown function of the component HTTP Server. Such manipulation leads to path traversal.

This vulnerability is listed as CVE-2026-64677. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.