Home

Description

In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed for a YouTube link in the deck. The executable name could be youtube-dl.exe or yt-dlp.exe or yt-dlp_x86.exe.

PUBLISHED Reserved 2025-10-07 | Published 2025-10-07 | Updated 2025-10-08 | Assigner mitre




MEDIUM: 6.7CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Problem types

CWE-427 Uncontrolled Search Path Element

Product status

Default status
unaffected

Any version before 25.02.5
affected

References

github.com/...ommit/5080451829505842b16d4a50f398ad44560a3e48

github.com/...commit/6213c9b6f99ebda181004f8915b92fe3618b939

github.com/ankitects/anki/compare/25.02.4...25.02.5

cve.org (CVE-2025-62185)

nvd.nist.gov (CVE-2025-62185)

Download JSON