SB20260917259 - Multiple vulnerabilities in Anki



SB20260917259 - Multiple vulnerabilities in Anki

Published: September 17, 2026

Security Bulletin ID SB20260917259
CSH Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Medium 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) External Control of File Name or Path (CVE-ID: N/A)

CWE-ID: CWE-73 - External Control of File Name or Path

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to external control of file name or path in the openFolder function in qt/aqt/utils.py when opening an image from a malicious flashcard deck in the editor. A remote attacker can embed an image tag with a path containing a dangerous extension in its src attribute and induce the victim to select the \"Open image\" action to execute arbitrary code.

User interaction is required to select the \"Open image\" action.


2) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to perform privileged desktop API operations.

The vulnerability exists due to improper neutralization of input during web page generation in the image-occlusion document when rendering imported note HTML. A remote attacker can provide crafted note HTML that is opened in the editor to perform privileged desktop API operations.

Exploitation requires a referenced note with a supported image whose identifier survives import remapping.


Remediation

Install update from vendor's website.