CVE-2024-26020Critical· 9.6▾ MidnightAnkitects Anki arbitrary script execution vulnerability
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.8 · likelihood 3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
15%
15% → 15%
An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability.
anki < 24.06Upgrade to a patched release:
anki 24.06Connected by shared product, vendor, weakness, or advisory.