{"id":"CVE-2024-26020","aliases":["GHSA-9gq7-p5w9-w899","PYSEC-2026-1116"],"title":"Ankitects Anki arbitrary script execution vulnerability","summary":"Ankitects Anki arbitrary script execution vulnerability","severity":"critical","cvss":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","vendor":"anki","product":"anki","ecosystem":"pip","affected":["anki < 24.06"],"patched":["anki 24.06"],"published":"2024-07-22","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-9gq7-p5w9-w899","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-26020"},{"url":"https://github.com/ankitects/anki/commit/8d2e8b1e4fa3757581f224b1a57057d0455352ce"},{"url":"https://github.com/ankitects/anki"},{"url":"https://skerritt.blog/anki-0day"},{"url":"https://skii.dev/anki-0day"},{"url":"https://talosintelligence.com/vulnerability_reports/TALOS-2024-1993"}],"tags":["osv","pip"],"epss":0.15186,"epssPercentile":0.96593,"ingestedAt":"2026-07-08T18:25:47.972Z","slug":"CVE-2024-26020","body":"## Overview\n\nAn arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability.\n\n## Affected packages\n\n- `anki < 24.06`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `anki 24.06`","depth":"midnight","depthScore":56,"depthScoreParts":{"impact":52.8,"likelihood":3,"exploitation":0,"ransomware":0},"changes":[]}