LOW3.1
PYSEC-2026-1117
Ankitects Anki LaTeX Blocklist Bypass vulnerability
Quick fix
PYSEC-2026-1117 — anki: upgrade to the fixed version with the command below.
pip install --upgrade 'anki>=24.6'Details
A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trigger this vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-32152[ADVISORY]
- https://github.com/ankitects/anki/pull/3218[WEB]
- https://github.com/ankitects/anki/commit/06f7aa393d21d7d5dd8039e15d543b73c3346932[WEB]
- https://github.com/ankitects/anki[PACKAGE]
- https://skerritt.blog/anki-0day[WEB]
- https://skii.dev/anki-0day[WEB]
- https://talosintelligence.com/vulnerability_reports/TALOS-2024-1994[WEB]
- https://pypi.org/project/anki[PACKAGE]
- https://github.com/advisories/GHSA-q47p-v5rw-v574[ADVISORY]