---
id: CVE-2024-32152
aliases:
  - GHSA-q47p-v5rw-v574
  - PYSEC-2026-1117
title: Ankitects Anki LaTeX Blocklist Bypass vulnerability
summary: Ankitects Anki LaTeX Blocklist Bypass vulnerability
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'
vendor: anki
product: anki
ecosystem: pip
affected:
  - anki < 24.6
patched:
  - anki 24.6
published: '2024-07-22'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-q47p-v5rw-v574'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-32152'
  - url: 'https://github.com/ankitects/anki/pull/3218'
  - url: >-
      https://github.com/ankitects/anki/commit/06f7aa393d21d7d5dd8039e15d543b73c3346932
  - url: 'https://github.com/ankitects/anki'
  - url: 'https://skerritt.blog/anki-0day'
  - url: 'https://skii.dev/anki-0day'
  - url: 'https://talosintelligence.com/vulnerability_reports/TALOS-2024-1994'
tags:
  - osv
  - pip
epss: 0.12741
epssPercentile: 0.96094
ingestedAt: '2026-07-08T18:25:52.088Z'
---

## Overview

A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trigger this vulnerability.

## Affected packages

- `anki < 24.6`

## Remediation

Upgrade to a patched release:

- `anki 24.6`
