---
id: CVE-2025-62187
title: >-
  In Ankitects Anki before 25.02.6, crafted sound file references could cause
  files to be written to arbitrary locations on Windows and Linux (media file
  pathnames are not necessarily relative to the media folder).
summary: >-
  In Ankitects Anki before 25.02.6, crafted sound file references could cause
  files to be written to arbitrary locations on Windows and Linux (media file
  pathnames are not necessarily relative to the media folder).
severity: low
cvss: 2.9
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-23
vendor: ankitects
product: anki
affected:
  - anki < 25.02.6
patched:
  - anki 25.02.6
published: '2025-10-07'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62187'
references:
  - url: 'https://github.com/ankitects/anki/pull/4041'
    label: cve@mitre.org
  - url: >-
      https://github.com/ankitects/anki/pull/4041/commits/51476e05b281737a0c2924342bccdb6e5be52ea9
    label: cve@mitre.org
  - url: 'https://github.com/ankitects/anki/releases/tag/25.02.6'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00177
epssPercentile: 0.06659
ingestedAt: '2026-10-08T13:42:54.984Z'
---

## Overview

In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux (media file pathnames are not necessarily relative to the media folder).

## Affected

- `anki < 25.02.6`

## Remediation

Upgrade past the affected range:

- `anki 25.02.6`
