CVE-2025-62187Low· 2.9▾ SunlitIn Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux (media file pathnames are not necessarily relative to the media folder).
▾ Sunlit zone — Low / medium · no exploitation signal
impact 16 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux (media file pathnames are not necessarily relative to the media folder).
anki < 25.02.6Upgrade past the affected range:
anki 25.02.6Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62185Medium· 6.7In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed for a YouTube link in the deck
CVE-2025-62186Medium· 6.7Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio because of URL scheme mishandling.
CVE-2024-29073Medium· 5.3Anki Latex Incomplete Blocklist Vulnerability
CVE-2024-32152Low· 3.1Ankitects Anki LaTeX Blocklist Bypass vulnerability
CVE-2024-26020Critical· 9.6Ankitects Anki arbitrary script execution vulnerability
CVE-2026-103663Medium· 6.9Ollama is vulnerable to path traversal in the `/api/pull` endpoint due to insufficient validation of layer digests by the `digestToPath` function