VDB
Sign up
LOW3.1

PYSEC-2026-1117

Ankitects Anki LaTeX Blocklist Bypass vulnerability

Quick fix

PYSEC-2026-1117 — anki: upgrade to the fixed version with the command below.

pip install --upgrade 'anki>=24.6'

Details

A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trigger this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/anki
Introduced in: 0Fixed in: 24.6
Fixpip install --upgrade 'anki>=24.6'

References