VYPR

PyPI package

anki

pkg:pypi/anki

Vulnerabilities (3)

  • CVE-2024-29073Jul 22, 2024
    affected < 24.6fixed 24.6

    An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe commands, the verbatim package, which comes installed by default in many Latex distributions, has been overlooked. A specially crafted flashcard can lead to an arbi

  • CVE-2024-26020Jul 22, 2024
    affected < 24.06fixed 24.06

    An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability.

  • CVE-2024-32152Jul 22, 2024
    affected < 24.6fixed 24.6

    A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trigger this vulnerability.