Home

Description

Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio because of URL scheme mishandling.

PUBLISHED Reserved 2025-10-07 | Published 2025-10-07 | Updated 2025-10-08 | Assigner mitre




MEDIUM: 6.7CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Problem types

CWE-829 Inclusion of Functionality from Untrusted Control Sphere

Product status

Default status
unaffected

Any version before 25.02.5
affected

References

github.com/ankitects/anki/releases/tag/25.02.5

cve.org (CVE-2025-62186)

nvd.nist.gov (CVE-2025-62186)

Download JSON