25.9.2
5 years ago
4 days ago
Known vulnerabilities in the anki package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Arbitrary Code Injection due to improper handling of MPV functionality in flashcards. The MPV component processes user-supplied flashcard content with insufficient sanitization, enabling crafted inputs to execute arbitrary scripts on Windows systems. An attacker can exploit this by distributing a specially crafted flashcard to a userresulting in arbitrary code execution within the user's context, potentially leading to full system compromise. How to fix Arbitrary Code Injection? Upgrade | [,24.6) |
Affected versions of this package are vulnerable to Incomplete List of Disallowed Inputs due to a LaTeX blocklist bypass in the LaTeX processing functionality. The LaTeX module fails to enforce its blocklist properly, allowing specially crafted malicious flashcards to create arbitrary files at a fixed path. An attacker can exploit this by sharing a malicious flashcard that, when imported or rendered by Anki, creates files at predetermined locations on the user’s system, potentially enabling further unwanted actions such as remote code execution. How to fix Incomplete List of Disallowed Inputs? Upgrade | [,24.6) |
Affected versions of this package are vulnerable to Inclusion of Functionality from Untrusted Control Sphere due to incomplete LaTeX sanitization that fails to block the How to fix Inclusion of Functionality from Untrusted Control Sphere? Upgrade | [,24.6) |
Affected versions of this package are vulnerable to Uncontrolled Search Path Element via the integration with Note: This vulnerability is specific to Windows operating systems due to the inclusion of the current working directory in the system PATH. How to fix Uncontrolled Search Path Element? Upgrade | [,25.2.5) |