CVE-2024-32152Low· 3.1▾ SunlitAnkitects Anki LaTeX Blocklist Bypass vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 2.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
12%
12% → 12%
A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trigger this vulnerability.
anki < 24.6Upgrade to a patched release:
anki 24.6Connected by shared product, vendor, weakness, or advisory.