CRITICAL9.6
PYSEC-2026-1116
Ankitects Anki arbitrary script execution vulnerability
Quick fix
PYSEC-2026-1116 — anki: upgrade to the fixed version with the command below.
pip install --upgrade 'anki>=24.06'Details
An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-26020[ADVISORY]
- https://github.com/ankitects/anki/commit/8d2e8b1e4fa3757581f224b1a57057d0455352ce[WEB]
- https://github.com/ankitects/anki[PACKAGE]
- https://skerritt.blog/anki-0day[WEB]
- https://skii.dev/anki-0day[WEB]
- https://talosintelligence.com/vulnerability_reports/TALOS-2024-1993[WEB]
- https://pypi.org/project/anki[PACKAGE]
- https://github.com/advisories/GHSA-9gq7-p5w9-w899[ADVISORY]