In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux (media file pathnames are not necessarily relative to the media folder).
References
Configurations
History
10 Oct 2025, 16:20
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/ankitects/anki/pull/4041 - Patch | |
| References | () https://github.com/ankitects/anki/pull/4041/commits/51476e05b281737a0c2924342bccdb6e5be52ea9 - Patch | |
| References | () https://github.com/ankitects/anki/releases/tag/25.02.6 - Release Notes | |
| CPE | cpe:2.3:a:ankitects:anki:*:*:*:*:*:*:*:* | |
| First Time |
Ankitects
Ankitects anki |
07 Oct 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-07 21:15
Updated : 2025-10-10 16:20
NVD link : CVE-2025-62187
Mitre link : CVE-2025-62187
CVE.ORG link : CVE-2025-62187
JSON object : View
Products Affected
ankitects
- anki
CWE
CWE-23
Relative Path Traversal
