Safety vulnerability ID: 78753
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of the Anki package are vulnerable to Arbitrary File Creation due to a LaTeX blocklist bypass in the LaTeX processing functionality. The LaTeX module in Anki (≤ 24.04) fails to enforce its blocklist properly, allowing specially crafted malicious flashcards to create arbitrary files at a fixed path. An attacker can exploit this by sharing a malicious flashcard that, when imported or rendered by Anki, creates files at predetermined locations on the user’s system, potentially enabling further unwanted actions such as remote code execution.
Latest version: 25.9
None
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application