Description
An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2309 | An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability. |
Github GHSA |
GHSA-9gq7-p5w9-w899 | Ankitects Anki arbitrary script execution vulnerability |
References
History
Tue, 04 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Sep 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ankiweb
Ankiweb anki |
|
| CPEs | cpe:2.3:a:ankiweb:anki:24.04:*:*:*:*:*:*:* | |
| Vendors & Products |
Ankiweb
Ankiweb anki |
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2025-11-04T17:14:34.137Z
Reserved: 2024-05-06T16:38:51.434Z
Link: CVE-2024-26020
Updated: 2025-11-04T17:14:34.137Z
Status : Modified
Published: 2024-07-22T15:15:02.660
Modified: 2025-11-04T18:15:54.510
Link: CVE-2024-26020
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA