Safety vulnerability ID: 78749
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of the Anki package are vulnerable to Code Injection due to improper handling of MPV functionality in flashcards. The MPV component processes user-supplied flashcard content without sufficient sanitization, enabling crafted inputs to execute arbitrary scripts. An attacker can exploit this by distributing a specially crafted flashcard to a user—which the Anki application renders via MPV—resulting in arbitrary code execution within the user's context, potentially leading to full system compromise.
Latest version: 25.9
None
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application