In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade anki
to version 25.2.5 or higher.
Affected versions of this package are vulnerable to Uncontrolled Search Path Element via the integration with mpv
, an attacker can achieve arbitrary code execution by including a malicious executable within a shared deck.
Note: This vulnerability is specific to Windows operating systems due to the inclusion of the current working directory in the system PATH.