---
id: CVE-2024-26020
aliases:
  - GHSA-9gq7-p5w9-w899
  - PYSEC-2026-1116
title: Ankitects Anki arbitrary script execution vulnerability
summary: Ankitects Anki arbitrary script execution vulnerability
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'
vendor: anki
product: anki
ecosystem: pip
affected:
  - anki < 24.06
patched:
  - anki 24.06
published: '2024-07-22'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-9gq7-p5w9-w899'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-26020'
  - url: >-
      https://github.com/ankitects/anki/commit/8d2e8b1e4fa3757581f224b1a57057d0455352ce
  - url: 'https://github.com/ankitects/anki'
  - url: 'https://skerritt.blog/anki-0day'
  - url: 'https://skii.dev/anki-0day'
  - url: 'https://talosintelligence.com/vulnerability_reports/TALOS-2024-1993'
tags:
  - osv
  - pip
epss: 0.15186
epssPercentile: 0.96628
ingestedAt: '2026-07-08T18:25:47.972Z'
---

## Overview

An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability.

## Affected packages

- `anki < 24.06`

## Remediation

Upgrade to a patched release:

- `anki 24.06`
