CVE-2025-62187

In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux (media file pathnames are not necessarily relative to the media folder).
Configurations

Configuration 1 (hide)

cpe:2.3:a:ankitects:anki:*:*:*:*:*:*:*:*

History

10 Oct 2025, 16:20

Type Values Removed Values Added
References () https://github.com/ankitects/anki/pull/4041 - () https://github.com/ankitects/anki/pull/4041 - Patch
References () https://github.com/ankitects/anki/pull/4041/commits/51476e05b281737a0c2924342bccdb6e5be52ea9 - () https://github.com/ankitects/anki/pull/4041/commits/51476e05b281737a0c2924342bccdb6e5be52ea9 - Patch
References () https://github.com/ankitects/anki/releases/tag/25.02.6 - () https://github.com/ankitects/anki/releases/tag/25.02.6 - Release Notes
CPE cpe:2.3:a:ankitects:anki:*:*:*:*:*:*:*:*
First Time Ankitects
Ankitects anki

07 Oct 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-07 21:15

Updated : 2025-10-10 16:20


NVD link : CVE-2025-62187

Mitre link : CVE-2025-62187

CVE.ORG link : CVE-2025-62187


JSON object : View

Products Affected

ankitects

  • anki
CWE
CWE-23

Relative Path Traversal